Friday, February 28, 2025
HomeCyber AttackBitPaymer Ransomware Attack Several Spanish MSSP Based Companies Via Hacked Websites

BitPaymer Ransomware Attack Several Spanish MSSP Based Companies Via Hacked Websites

Published on

SIEM as a Service

Follow Us on Google News

A new wave of BitPaymer Ransomware attack several MSSP based companies in Spain through compromised websites, and it’s using various other malware interaction before infecting the company network.

Before the original BitPaymer ransomware attack takes place, threat actors initially infect the victims with a different type of malware such as AzorultChthonicDridex.

Last 2 years, ransomware attacks are dramatically increased, and more ransomware threats are attacking the high-value targets in all kinds of sectors.

Researchers observed that the attackers using some of the old TTPs that observed a year back, and now use additional methods such as privilege escalation, lateral movement, and internal reconnaissance.

BitPaymer Ransomware
Infection flow visualization (click to enlarge the image)

BitPaymer Ransomware Infection Process

The initial stage of infection starts with a malicious URL that pointed to the fake or compromised websites, and in some cases, it pointed to the legitimate website by using a pay-per-install service.

Attackers trick the victims using social engineering techniques to download the desired application to drop the next stage of malware to start the first level of infection.

Malware includes Azorult, Chthonic, Dridex that allows an attacker to gain remote access and drop further exploits such as additional malware and post-exploitation tools.

According to Mcafee analysis, “For quite some time now, Dridex’s behavior has changed from its original form. Less Dridex installs are linked to stealing banking info and more Dridex infections are becoming a precursor to a targeted ransomware attack.”

Once the malware infects the multiple machines, it collects as many credentials and also threat actors using a post-exploitation tool called Mimikatz to credentials and re-use them internally to execute additional software in the Active Directory servers or other machines inside the network.

Mimikatz is wide used post-exploitation tool, and it observed that the use of at least 20 different threat actors for various attacks.

Attackers also using a PowerShell script to automate certain things and used to find specific folders inside the infected systems.

Ransomware Execution

After collecting enough high privileged accounts, and gained control over the Active Directory, then they start to distribute and execute the ransomware in the complete network.

“The actors behind BitPaymer invest time to know their victims and build a custom binary for each which includes the leet-speek name of the victim as the file extension for the encrypted files, i.e. “financials.<name_of_victim>”. Mark Rivero from Mcafee said.

BitPaymer Ransomware

Companies must not ignore indicators of activity from malware like Dridex, Azorult or NetSupport; they could be a first indicator of other malicious activity to follow.

Researchers unclear about how the fake link arrived to the victims, but most likely SPAM campaigns were most likely used to deliver the malware.

It worth mention that, last month BitPaymer Ransomware exploit Apple iTunes for Windows Zero-day to attacker public and private sectors across the U.S.

You can also read the complete Ransomware Attack Response and Mitigation Checklist.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

DeepSeek Data Leak Exposes 12,000 Hardcoded API Keys and Passwords

A sweeping analysis of the Common Crawl dataset—a cornerstone of training data for large...

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Unpatched Vulnerabilities Attract Cybercriminals as EDR Visibility Remains Limited

Cyber adversaries have evolved into highly organized and professional entities, mirroring the operational efficiency...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Threat Actors Attack Job Seekers of Fortune 500 Companies to Steal Personal Details

In Q3 2024, Cofense Intelligence uncovered a targeted spear-phishing campaign aimed at employees working...