The new version of the HardBit 4.0 ransomware: A growing threat to corporate cybersecurity

Cybersecurity researchers have discovered a new version of the HardBit ransomware, known as HardBit 4.0, which uses password protection to evade detection. Unlike previous versions, this variant requires a password to run properly, making analysis more difficult for security researchers. HardBit, which first appeared in October 2022, is notable for the absence of a data leak site, instead threatening victims with further attacks to force them to pay.

The initial access vector is unclear, but may involve brute-forcing RDP and SMB services. Once access has been gained, the attackers use tools such as Mimikatz to steal credentials and move laterally via RDP. HardBit disables antivirus software and Microsoft Defender services, and encrypts files on the infected host. It also offers a ‘wiper’ mode to permanently delete files. In 2024, ransomware attacks are on the rise, with significant activity from the LockBit, Akira and BlackSuit groups.

https://thehackernews.com/2024/07/new-hardbit-ransomware-40-uses.html

Source: The Hacker News