CSIDB logo
Incident

Ministerio de Agricultura de Chile

Incident posture

Attack window
Jun 2019
Location
Chile
Status
Historical
CIA posture
Available to members
Updated
2025-11-04 00:00

Linked entities

Victim
Ministerio de Agricultura de Chile
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Chilean Ministry of Agriculture was targeted in a ransomware attack affecting servers connected to its public services, attributed to the DoppelPaymer strain. This malware, derived from BitPaymer's code with enhanced features like threaded encryption for faster operation, demanded substantial ransom payments. Researchers identified strong technical links between the two ransomware families, including near-identical payment portals, suggesting DoppelPaymer may have been developed by a former BitPaymer affiliate. The incident disrupted operations and compromised data integrity within the ministry's infrastructure.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In mid-2019, a ransomware strain named DoppelPaymer was identified by malware researchers, with evidence of attacks occurring since at least mid-June. The ransomware shared significant code similarities with BitPaymer, an established threat, including an almost identical payment portal interface bearing the "Bit paymer" title. Researchers from CrowdStrike's research and threat intelligence team analyzed eight variants of DoppelPaymer, tracing the earliest sample back to April 2019. Among confirmed victims was the Chilean Ministry of Agriculture, where servers connected to a public service under the ministry were compromised. Chile's Computer Security Incident Response Team (CSIRT) publicly acknowledged the ransomware attack on July 1, 2019, though the exact intrusion timeline within June remained unspecified. The attack disrupted ministry-related systems, though the specific operational impacts were not detailed in public reports.

Technical analysis revealed DoppelPaymer incorporated enhancements over BitPaymer, such as a threaded encryption process designed to accelerate file-locking operations. CrowdStrike researchers Brett Stone-Gross, Sergei Frankoff, and Bex Hartley noted the code overlap and portal similarities strongly suggested the involvement of a former BitPaymer affiliate operating a new ransomware operation. The attackers demanded cryptocurrency ransoms, exemplified by a concurrent attack on the City of Edcouch, Texas, where decryption required payment of 8 BTC (approximately $60,000-$70,000 at the time). No ransom amount was disclosed for the Chilean incident. The Chilean CSIRT's confirmation represented the primary documented response action, though specific containment measures or decryption outcomes were not publicly reported. The incident highlighted DoppelPaymer's targeting of government entities during its early deployment phase.

Sources

Sources available to members: 1 source.

CSIDB