Threat Advisory

HardBit ransomware wants insurance details to set the perfect price

Threat: Ransomware
Targeted Region: Global
Targeted Sector: Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

 

Summary:[/subscribe_to_unlock_form]

 

Summary:[emaillocker id="1283"]

The New HardBit Ransomware version 2.0 threat has been discovered by researchers. The threat actor makes an attempt to convince the victim that it is in their interest to provide all insurance information so they may modify their requests so the insurer would cover all costs. This ransomware has the ability to disable Windows Defender, real-time behaviour monitoring process scan, and access file protection by modifying the Registry. The malware also targets 86 processes in order to terminate them and allow the encryption of sensitive files. The malware gains persistence in the system and makes data recovery more challenging. HardBit 2.0 Open the files, which replaces their existing contents with encrypted information in addition to making the encryption slightly faster, this method makes it harder for experts to recover the original files.

 

Threat Profile:

Tactic Technique Id Technique
 Reconnaissance T1592 Gather Victim Host Information
Execution T1059 Command and Scripting Interpreter
 Persistence T1547 Boot or Logon Autostart Execution
 Defense Evasion T1027 Obfuscated Files or Information
T1112 Modify Registry
T1562 Impair Defenses
T1036 Masquerading
Discovery T1082 System Information Discovery
Collection T1005 Data from Local System
Impact T1486 Data Encrypted for Impact
T1489 Service Stop

 

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/hardbit-ransomware-wants-insurance-details-to-set-the-perfect-price/

[/emaillocker]
crossmenu