HardBit 4.0 Ransomware Actors Attack Open RDP and SMB Services to Persist Access
The HardBit ransomware has introduced a new version, HardBit 4.0, which presents enhanced capabilities for evading detection and maintaining system control. This updated variant continues the evolution of the ransomware strain active since 2022.
The HardBit ransomware has introduced a new version, HardBit 4.0, which presents enhanced capabilities for evading detection and maintaining system control. This updated variant continues the evolution of the ransomware strain active since 2022.
HardBit 4.0 distinguishes itself from other ransomware groups by not employing a public data leak site for double extortion. Instead, it focuses exclusively on encryption-based ransom demands.
The attack methodology involves targeting vulnerable network infrastructure entry points. Picus Security analysts have identified that HardBit 4.0 actors gain initial access via brute-force attacks on open Remote Desktop Protocol ( RDP ) and Server Message Block (SMB) services. Once access is achieved, attackers focus on credential harvesting to facilitate lateral movement across the network.
HardBit 4.0 uses a multi-stage deployment strategy, making it difficult to detect. The malware leverages Neshta, a file-infecting virus active since 2003, as a dropper to deliver and execute HardBit 4.0. Neshta's mode of operation includes modifying executable files and manipulating the registry to establish persistence.
This updated variant continues the evolution of the ransomware strain active since 2022.
The deployment process involves extracting the HardBit payload from memory, decrypting its components, and executing the ransomware using legitimate Windows functions. Persistence is achieved by copying Neshta to the system root directory and altering registry keys to prioritize its execution.
HardBit 4.0 employs advanced defense evasion techniques, directly targeting security software. It modifies Windows Registry entries to disable features in Windows Defender, including Real-Time Monitoring, Tamper Protection, and Anti-Spyware capabilities. Additionally, the binary is obfuscated with a modified ConfuserEx protector to hinder analysis.
A notable feature of HardBit 4.0 is its passphrase protection mechanism, which requires specific authorization keys at runtime. This measure prevents accidental or automated sandbox detonation that could reveal its behavior to researchers.
Organizations can strengthen defenses against HardBit 4.0 by monitoring suspicious RDP and SMB activity, implementing robust credential management practices, and ensuring backup systems are isolated from network access to maintain recovery options.
Based on reporting by Cyber Security News.
