Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

HardBit 4.0 Ransomware Abuses Unsecured RDP and SMB for Access Persistence

## Cybersecurity: HardBit Ransomware Version 4.0 Overview

Cybersecurity: HardBit Ransomware Version 4.0 Overview

HardBit ransomware has released version 4.0, which includes advanced mechanisms for maintaining persistence through vulnerable network services.

This new variant utilizes open Remote Desktop Protocol (RDP) and Server Message Block (SMB) services as entry points. These enable threat actors to sustain long-term access to compromised networks while deploying advanced evasion techniques that complicate security analysis and response efforts.

HardBit 4.0 employs the Neshta file infector as a dropper mechanism, a significant departure from previous methods. Neshta, active since 2003, serves as the initial infection vector by decrypting and extracting the HardBit payload from its own binary before executing it.

Upon infection, the malware establishes persistence by copying itself to the Windows system directory and modifying registry keys to launch automatically when executable files are opened. This ensures continued presence even after system reboots.

The attack chain begins with brute-force attacks targeting open RDP and SMB services using tools such as NLBrute. Once access is secured, a custom batch script containing Mimikatz is deployed to harvest credentials from compromised systems.

HardBit ransomware has released version 4.0, which includes advanced mechanisms for maintaining persistence through vulnerable network services.
Nathan Cole · Thehackingpost

The harvested credentials allow attackers to move laterally across the network using legitimate remote access protocols, expanding their foothold without triggering traditional perimeter defenses.

Subsequent to credential theft, threat actors perform network reconnaissance using KPortScan 3.0 to identify additional RDP endpoints on port 3389 and Advanced Port Scanner for broader network enumeration. The 5-NS new.exe utility identifies available network shares, enabling multiple access points throughout the infrastructure.

A distinctive feature of HardBit 4.0 is its runtime authorization requirement, necessitating specific authorization credentials before execution. This complicates sandbox analysis and automated detection. The malware also aggressively disables Windows Defender through registry modifications and PowerShell commands, targeting Tamper Protection, Real-Time Monitoring, and Anti-Spyware features.

Before encryption begins, HardBit stops critical services, including backup software and security tools. The malware then deletes shadow copies and disables the Windows boot status policy, preventing recovery without paying the ransom. Encrypted files are marked with custom icons, and the desktop wallpaper is replaced with a ransom notice.

Advertisement

The GUI version of HardBit 4.0 includes a "Wiper" mode activated through configuration files. When enabled, the malware permanently destroys data rather than encrypting it, offering an option for operators prioritizing data destruction over extortion.

Organizations are advised to secure RDP and SMB services through network segmentation, strong authentication, and continuous monitoring. Implementing behavioral detection for Mimikatz execution and network scanning activities can disrupt the attack chain before lateral movement occurs. Regular security updates and comprehensive backup solutions are essential to mitigating HardBit ransomware threats.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories