4bid
SHADOW-VOID-042, Storm-0978, Tropical Scorpius, APT44
4bid has emerged as one of the most active threat actors in recent years, targeting a broad array of sectors including government, defense, aerospace, energy, healthcare, manufacturing, logistics, education and maritime. In late‑2025 and early‑2026 the group leveraged updated versions of its custom Rust‑based dropper to stage Blackout Locker, deploying it via an obfuscated .dat file written to user AppData and renamed to .exe by cmd.exe. This technique is combined with a suite of backdoors – GoRed (Bulldog), ZeronetKit, BlackReaperRAT, Tuoni, Cobalt Strike, DEEPROOT and others – which are installed either through spear‑phishing attachments or by exploiting zero‑day vulnerabilities such as ProxyShell in Microsoft Exchange and various misconfigurations in Veeam backup, WatchGuard and Confluence.
To maintain persistence and facilitate lateral movement the actors use legitimate remote‑access tools including AnyDesk, Panorama9 RMM, ScreenConnect and Splashtop, often bypassing or disabling endpoint protection via BYOVD drivers, signed malware, DLL sideloading, and reverse SSH tunnels. Credential theft is executed through DCSync, LSASS dumping with Mimikatz, and password spraying on VNC/SSH services, while exfiltration frequently occurs to C2 servers over DNS‑over‑HTTPS or encrypted channel protocols such as AES/ChaCha20.
4bid’s recent operations also demonstrate a strategic shift toward monetization: ransomware campaigns such as Blackout Locker and ClearWater now accompany extensive surveillance via backdoors that collect system data, capture screens, harvest cloud credentials, and sabotage industrial control systems. The group has shown an ability to co‑operate with allied threat complexes (e.g., BO Team, Red Likho) by sharing infrastructure and targeting patterns, further amplifying their operational tempo.
The actor’s use of both political motives—often framing attacks in a pro-Ukrainian context—and clear financial incentives reflects a hybrid model that enables rapid escalation across borders while capitalizing on the high-value targets within critical sectors.
Ransomware
APT
Backdoor / C2
DDoS
+86