Summary:[/subscribe_to_unlock_form]
Summary:[emaillocker id="1283"]
The New HardBit Ransomware version 2.0 threat has been discovered by researchers. The threat actor makes an attempt to convince the victim that it is in their interest to provide all insurance information so they may modify their requests so the insurer would cover all costs. This ransomware has the ability to disable Windows Defender, real-time behaviour monitoring process scan, and access file protection by modifying the Registry. The malware also targets 86 processes in order to terminate them and allow the encryption of sensitive files. The malware gains persistence in the system and makes data recovery more challenging. HardBit 2.0 Open the files, which replaces their existing contents with encrypted information in addition to making the encryption slightly faster, this method makes it harder for experts to recover the original files.
Threat Profile:
| Tactic | Technique Id | Technique |
| Reconnaissance | T1592 | Gather Victim Host Information |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1112 | Modify Registry | |
| T1562 | Impair Defenses | |
| T1036 | Masquerading | |
| Discovery | T1082 | System Information Discovery |
| Collection | T1005 | Data from Local System |
| Impact | T1486 | Data Encrypted for Impact |
| T1489 | Service Stop |
References:
The following reports contain further technical details:
[/emaillocker]