BitPaymer Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
March 25, 2026
Last Seen
July 23, 2026

Related Threat Clusters

  • Operation Endgame Disrupts Evil Corp's SocGholish Malware Network

    On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…

    67 articles · Updated June 18, 2026
  • MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

    In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…

    16 articles · Updated July 22, 2026
  • EU Sanctions Vitaly Kovalev, Ransomware Leader of Trickbot Group

    On July 14, 2026, the European Union, in coordination with the U.S. and U.K., sanctioned Vitaly Nikolayevich Kovalev, known as 'Stern,' a key figure in the Trickbot ransomware syndicate. Kovalev is linked to over $300…

    4 articles · Updated July 15, 2026
  • Russian Access Broker Sentenced for $9M Ransomware Facilitation

    Aleksei Volkov, a 26-year-old Russian citizen, was sentenced to 81 months in prison for his role as an initial access broker (IAB) facilitating ransomware attacks against U.S. companies, including the Yanluowang group.…

    21 articles · Updated March 24, 2026

Recent Intelligence Reports

  • 001 — attack.mitre.org · July 23, 2026
  • “Stern” Ransomware Operator Sanctioned by EU — Chainalysis · July 14, 2026
  • Are The Notorious Cyber Criminals Evil Corp Actually Russian Spies — www.truesec.com · June 18, 2026
  • Manager of botnet used in ransomware attacks gets 2 years in prison — Bleepingcomputer · March 25, 2026

CVSS v3.1 Breakdown