HomeSecurityHardBit Ransomware 4.0: New techniques for avoiding detection

HardBit Ransomware 4.0: New techniques for avoiding detection

Security researchers have shed light on a new version (version 4.0) of the HardBit ransomware, which uses new techniques to evade detection.

HardBit Ransomware 4.0 evasion of detection

“ Unlike previous versions, the HardBit ransomware team has improved version 4.0 with passphrase protection ,” said Cybereason researchers Kotaro Ogino and Koshi Oyama . “ The passphrase must be provided during runtime in order for the ransomware to execute properly. The additional obfuscation prevents security researchers from analyzing the malware .”

HardBit ransomware first appeared in October 2022. The hackers behind it are financially motivated and use double blackmail tactics.

See also: Indiana County Hit by Devastating Ransomware Attack

The group does not have a data, but it pressures victims to pay, threatening additional attacks in the future. Communication is primarily via the Tox instant messaging service.

The method of initial access of HardBit ransomware to the target network is currently unclear, although it is suspected to involve brute-forcing attacks on RDP and SMB services.

Once accessed, credential theft is performed using tools such as Mimikatz and NLBrute. Network analysis is also performed using utilities such as Advanced Port Scanner, allowing attackers to move around the network via RDP.

“After a host is compromised, the HardBit ransomware payload is executed and performs a series of steps that reduce the host’s security posture, before encrypting the victim’s data,” Varonis noted in a report on HardBit 2.0 last year.

The encryption of the victim's computers is carried out by the HardBit development, which is delivered using a well-known file-infecting virus, called Neshta.

See also: Indonesia boosts cybersecurity after ransomware attack

HardBit ransomware is also designed to disable Microsoft Defender Antivirus and terminate processes and services to avoid potential detection by security systems and researchers. It then encrypts files, updates their icons, and changes the desktop wallpaper and system volume label, writing “Locked by HardBit.

In addition to being offered to operators in the form of command-line or GUI versions, HardBit ransomware requires an authorization ID in order to execute successfully.

HardBit Ransomware 4.0: New techniques for avoiding detection

Ransomware protection

Back up your data: One of the most effective ways to protect yourself from a ransomware attack is to regularly back up data . This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.

Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest security and software updates to prevent any vulnerabilities that could be exploited by ransomware (e.g. HardBit).

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Beware of suspicious emails and links:  Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.

See also: Ransomware attacks on the rise despite law enforcement efforts

Use antivirus software:  Installing reputable antivirus software on your devices can help you detect and prevent ransomware attacks (e.g. HardBit). Be sure to update your antivirus to ensure it is equipped to handle new threats.

Education: One of the most important steps in protecting against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.

Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.

Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks (e.g. HardBit). This is especially important when using public Wi-Fi, which are often unsecured and vulnerable to cyberattacks.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS