DoppelPaymer Ransomware
First observed in April 2019, DoppelPaymer is a ransomware tool based on the older BitPaymer malware.
Summary
First observed in April 2019, DoppelPaymer is a ransomware tool based on the older BitPaymer malware.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how DoppelPaymer is distributed. However, it's similarities with BitPaymer suggest it may employ the same delivery vectors, including over insecure Remote Desktop Protocol connections or via spam campaigns.
Once installed, DoppelPaymer will check for a specific command line argument, terminating itself if this is not present, in an attempt to prevent automated analysis. It will then terminate anti-virus, backup, database and email processes using the open-source ProcessHacker tool. DoppelPaymer will encrypt all local non-system files using an AES-256 algorithm, the key for which is then itself encrypted using a hard-coded RSA-4096 key.
DoppelPaymer can also attempt to enumerate the local network by parsing the affected system's Address Resolution Protocol table to gather connected host IP addresses.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:49 pm