New HardBit Ransomware 4.0 Uses Passphrase Protection to Evade Detection
ID: 8fc5cc3f-6186-5de5-af0d-9ece481e7775
STIX ID: report--8fc5cc3f-6186-5de5-af0d-9ece481e7775
Feed Name: The Hacker News
**Executive summary:** Cybersecurity researchers reported a new HardBit ransomware v4.0 that introduces runtime passphrase protection and stronger obfuscation to impede analysis; operators leverage brute-forced RDP/SMB, credential theft (Mimikatz/NLBrute), lateral movement via RDP, delivery via Neshta, and can disable Microsoft Defender and other services, with an optional wiper mode enabled via a configuration file (hard.txt); HardBit communicates over Tox and uses double-extortion tactics without a public leak site.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
