logo

HardBit 4.0 Ransomware Analysis

ID: aaf1fa86-a801-5966-bcef-83603c2adfea

STIX ID: report--aaf1fa86-a801-5966-bcef-83603c2adfea

Feed Name: Resources-2

Threat Score
78/100

Date Published: 2025-12-20

Date Updated: 2026-07-22

Author: Picus Labs

...
...

HardBit 4.0 is a destructive ransomware variant delivered via the Neshta file-infector which drops and executes a .NET-obfuscated payload that requires a runtime authorization ID and encryption key; it provides both CLI and GUI builds (the latter offering an optional 'Wiper' mode), uses RDP/SMB brute force and Mimikatz for lateral movement, aggressively disables Windows Defender and backup/recovery features, and stops protective services to maximize impact. The report also documents the attackers' use of scanning tools, persistence via registry modification, and recommends simulating attacks with the Picus platform to validate defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.