{"id":30233,"date":"2024-07-17T11:32:21","date_gmt":"2024-07-17T09:32:21","guid":{"rendered":"https:\/\/www.arc-data-shield.fr\/?p=30233"},"modified":"2024-07-19T08:23:43","modified_gmt":"2024-07-19T06:23:43","slug":"la-nouvelle-version-de-hardbit-4-0-une-menace-accrue-pour-la-cybersecurite-des-entreprises","status":"publish","type":"post","link":"https:\/\/www.arc-data-shield.fr\/en\/la-nouvelle-version-de-hardbit-4-0-une-menace-accrue-pour-la-cybersecurite-des-entreprises\/","title":{"rendered":"The new version of the HardBit 4.0 ransomware: An increased threat to corporate cybersecurity"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Cybersecurity researchers have discovered a new version of HardBit ransomware, named HardBit 4.0, which uses password protection to avoid detection. Unlike previous versions, this variant requires a password to run correctly, making analysis more difficult for security researchers. HardBit, which first appeared in October 2022, is distinguished by the absence of a data leak site, preferring to threaten victims with new attacks to force them to pay. <\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"940\" height=\"302\" src=\"https:\/\/www.arc-data-shield.fr\/wp-content\/uploads\/2024\/07\/hackthenews.png\" alt=\"\" class=\"wp-image-30235\" style=\"width:449px;height:auto\" srcset=\"https:\/\/www.arc-data-shield.fr\/wp-content\/uploads\/2024\/07\/hackthenews.png 940w, https:\/\/www.arc-data-shield.fr\/wp-content\/uploads\/2024\/07\/hackthenews-480x154.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 940px, 100vw\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The initial access vector is unclear, but could involve brute force of RDP and SMB services. Once access has been gained, attackers use tools such as Mimikatz for credential theft and lateral movement via RDP. HardBit disables antivirus and Microsoft Defender services, and encrypts files on the infected host. It also offers a wiper mode for permanent file deletion. In 2024, ransomware attacks are on the rise, with strong activity from the LockBit, Akira and BlackSuit groups.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2024\/07\/new-hardbit-ransomware-40-uses.html\">https:\/\/thehackernews.com\/2024\/07\/new-hardbit-ransomware-40-uses.html<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Credits : <em><a href=\"https:\/\/thehackernews.com\/2024\/07\/new-hardbit-ransomware-40-uses.html\" data-type=\"link\" data-id=\"https:\/\/thehackernews.com\/2024\/07\/new-hardbit-ransomware-40-uses.html\">The Hacker news<\/a><\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Des chercheurs en cybers\u00e9curit\u00e9 ont d\u00e9couvert une nouvelle version du ransomware HardBit, nomm\u00e9e HardBit 4.0, qui utilise une protection par mot de passe pour \u00e9viter la d\u00e9tection. Contrairement aux versions pr\u00e9c\u00e9dentes, cette variante n\u00e9cessite un mot de passe pour s&rsquo;ex\u00e9cuter correctement, rendant l&rsquo;analyse plus difficile pour les chercheurs en s\u00e9curit\u00e9. HardBit, apparu pour la premi\u00e8re [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":30236,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"off","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[20],"tags":[],"class_list":["post-30233","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-commonnews"],"_links":{"self":[{"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/posts\/30233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/comments?post=30233"}],"version-history":[{"count":2,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/posts\/30233\/revisions"}],"predecessor-version":[{"id":30241,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/posts\/30233\/revisions\/30241"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/media\/30236"}],"wp:attachment":[{"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/media?parent=30233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/categories?post=30233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.arc-data-shield.fr\/en\/wp-json\/wp\/v2\/tags?post=30233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}