In the latest cybersecurity incident, HardBit ransomware version 4.0 has been deployed, utilizing advanced obfuscation techniques to evade detection and complicate the efforts by security analysts. By deleting Volume Shadow Copies and manipulating system recovery options, the ransomware incapacitates victims' ability to restore encrypted files. Persistent attacks are executed by mimicking legitimate system processes and disabling Windows Defender features. Although the initial method of spreading is undetermined, it's suspected to involve brute force attacks. This serious breach in security has the potential to disrupt operations, escalate to significant financial and reputational damages, and cause customer and employee data leaks.
Source: https://securityaffairs.com/165735/malware/hardbit-ransomware-version-4-0.html
TPRM report: https://scoringcyber.rankiteo.com/company/code-hunter
"id": "cod000071824",
"linkid": "code-hunter",
"type": "Ransomware",
"date": "7/2024",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"
{'attack_vector': 'Brute force attacks',
'data_breach': {'data_encryption': 'Encrypted files',
'type_of_data_compromised': ['Customer data',
'Employee data']},
'description': 'HardBit ransomware version 4.0 has been deployed, utilizing '
'advanced obfuscation techniques to evade detection and '
'complicate the efforts by security analysts. By deleting '
'Volume Shadow Copies and manipulating system recovery '
"options, the ransomware incapacitates victims' ability to "
'restore encrypted files. Persistent attacks are executed by '
'mimicking legitimate system processes and disabling Windows '
'Defender features. Although the initial method of spreading '
"is undetermined, it's suspected to involve brute force "
'attacks. This serious breach in security has the potential to '
'disrupt operations, escalate to significant financial and '
'reputational damages, and cause customer and employee data '
'leaks.',
'impact': {'data_compromised': ['Customer data', 'Employee data']},
'ransomware': {'data_encryption': 'Encrypted files',
'ransomware_strain': 'HardBit 4.0'},
'title': 'HardBit Ransomware 4.0 Incident',
'type': 'Ransomware'}