HardBit ransomware has been updated to version 2.0 and its operators are trying to negotiate a ransom payment that could be covered by the victim's insurance company.
Specifically, the threat actor tries to convince the victim that it is in his interest to disclose all insurance details so that he can adjust his claims so that the insurer covers all expenses.
See also: GoDaddy: Hackers stole source code and installed malware on servers

HardBit 2.0 Appearance
The first version of HardBit was detected in October 2022, while version 2.0 was introduced in November 2022 and is still the currently circulating variant, according to a report by Varonis, a data security and analytics company.
Unlike most ransomware operations, HardBit does not have a data leak website, although its operators claim to steal victims' data and threaten to leak it unless a ransom is paid.
As a ransomware strain, HardBit 2.0 has some capabilities to reduce the victim's security, such as modifying the registry to disable Windows Defender real-time behavior monitoring, process scanning, and on-access file protections.
The malware also targets 86 processes for termination so that sensitive files are available for encryption. It restores persistence by adding itself to the “Startup” folder and deletes Volume Shadow copies to make data recovery more difficult.
See also: Earth Kitsune: Uses new WhiskerSpy malware in its attacks
An interesting thing about the encryption phase is that instead of writing encrypted data to copies of files and deleting the originals like many strains do, HardBit 2.0 opens the files and replaces their contents with encrypted data. This approach makes it harder for experts to recover the original files and makes the encryption process slightly faster.
Ransom negotiation
Like other ransomware strains, the note that HardBit 2.0 drops on the victim's system does not inform about the amount of money the hackers want in exchange for the decryption. Victims have 48 hours to contact the attacker via an open-source encrypted peer-to-peer messaging application.

The threat actor advises victims not to cooperate with intermediaries, as this would only increase the overall cost, but to contact them directly for negotiations.
For companies that have cyber insurance, hackers have a more complex set of instructions and urge them to disclose the insurance amount for successful dialogue.
Hackers claim that sharing insurance details is beneficial to the victim, portraying the insurer as the bad guy who prevents their data from being recovered.
Threat actors say that insurers never negotiate with ransomware carriers with their clients' interests in mind, so they make ridiculous counteroffers to their claims simply to derail negotiations and refuse to pay.
See also: Cyberattack targets Coinbase employees with fake SMS alert
The attackers say that if they know the exact amount of insurance, they will know exactly how much to ask for, so the insurer is forced to meet the demand.
The Varonis report provides technical details on how HardBit 2.0 works, starting from the initial stage and disabling security features to obtaining persistence and deploying the encryption routine.
Information source: bleepingcomputer.com
