logo

HardBit 4.0 Ransomware Actors Attack Open RDP and SMB Services to Persist Access

ID: c4b09e17-0855-5b18-9dea-fabdcb70e9f7

STIX ID: report--c4b09e17-0855-5b18-9dea-fabdcb70e9f7

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**HardBit 4.0 ransomware** is an evolved, encryption-focused strain delivered via a Neshta file-infecting dropper that enables initial access through RDP/SMB brute-force, harvests credentials for lateral movement, achieves persistence via registry modifications, disables Windows Defender features, employs ConfuserEx-based obfuscation, and uses a runtime passphrase to hinder sandbox analysis; operators currently appear to focus on encryption-only extortion rather than public data leaks, and mitigations include monitoring RDP/SMB, enforcing strong credential management, and maintaining offline backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.