logo

Hardening of HardBit

ID: a32d988b-b6bc-5a5b-8c6f-0c46d5cfa9ef

STIX ID: report--a32d988b-b6bc-5a5b-8c6f-0c46d5cfa9ef

Feed Name: Cybereason Blog

Threat Score
75/100

Date Published: 2024-07-10

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason analyzes HardBit Ransomware v4.0, describing NESHTA-based delivery that drops a password-protected, obfuscated .NET ransomware available as CLI or GUI (with optional wiper mode). The report documents observed initial access via RDP/SMB brute force, credential theft (Mimikatz), network discovery, lateral movement, disabling of Windows Defender and shadow-copy deletion, provides IoCs (files, services, processes, registry keys), maps behaviors to MITRE ATT&CK, and recommends detection and prevention measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.