Also known as: SHADOW-VOID-042, Storm-0978, Tropical Scorpius, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, RomCom, the Bulldog backdoor, defense-industry organizations, Smoke Sandstorm, TA455, Yellow Liderc, Tortoiseshell, aviation, defense industries, LuoYu, foreign entities, Qilin, file transfer tools, APT35, Imperial Kitten, Blue Echidna, UNC2596, GOFFEE, Fluffy Wolf, CASCADE PANDA
4bid has emerged as one of the most active threat actors in recent years, targeting a broad array of sectors including government, defense, aerospace, energy, healthcare, manufacturing, logistics, education and maritime. In late‑2025 and early‑2026 the group leveraged updated versions of its custom Rust‑based dropper to stage Blackout Locker, deploying it via an obfuscated .dat file written to user AppData and renamed to .exe by cmd.exe. This technique is combined with a suite of backdoors – GoRed (Bulldog), ZeronetKit, BlackReaperRAT, Tuoni, Cobalt Strike, DEEPROOT and others – which are installed either through spear‑phishing attachments or by exploiting zero‑day vulnerabilities such as ProxyShell in Microsoft Exchange and various misconfigurations in Veeam backup, WatchGuard and Confluence. To maintain persistence and facilitate lateral movement the actors use legitimate remote‑access tools including AnyDesk, Panorama9 RMM, ScreenConnect and Splashtop, often bypassing or disabling endpoint protection via BYOVD drivers, signed malware, DLL sideloading, and reverse SSH tunnels. Credential theft is executed through DCSync, LSASS dumping with Mimikatz, and password spraying on VNC/SSH services, while exfiltration frequently occurs to C2 servers over DNS‑over‑HTTPS or encrypted channel protocols such as AES/ChaCha20. 4bid’s recent operations also demonstrate a strategic shift toward monetization: ransomware campaigns such as Blackout Locker and ClearWater now accompany extensive surveillance via backdoors that collect system data, capture screens, harvest cloud credentials, and sabotage industrial control systems. The group has shown an ability to co‑operate with allied threat complexes (e.g., BO Team, Red Likho) by sharing infrastructure and targeting patterns, further amplifying their operational tempo. The actor’s use of both political motives—often framing attacks in a pro-Ukrainian context—and clear financial incentives reflects a hybrid model that enables rapid escalation across borders while capitalizing on the high-value targets within critical sectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
4Bid is a financial‑driven threat actor that blends ransomware, persistent RAT deployments, and industrial sabotage to monetize high‑value targets across government, defense, energy, and critical infrastructure worldwide. Leveraging a Rust‑based dropper, the group stages Blackout Locker or ClearWater while installing backdoors such as AnyDesk, GoRed, and ZeronetKit for long‑term persistence and lateral movement. 4Bid’s hybrid profile—combining spear‑phishing, zero‑day exploitation, and legitimate remote‑access tools—enables rapid escalation across borders.
Goals & Targeting
4Bid pursues dual objectives: first, to extract monetary gain through ransomware and extortion; second, to conduct espionage and sabotage against strategic industries. The actor’s targeting profile focuses on both public utilities (energy, water, airports) and private sectors (defense contractors, aerospace, finance), leveraging insider‑like access conferred by remote‑access tools and exploited misconfigurations. By combining ransomware shock value with stealthy persistence via RATs and distributed infrastructure, 4Bid seeks to maintain long‑term footholds in high‑value environments while expanding reach into new geographic markets such as the UAE, Kazakhstan, Syria, and Egypt.
Enhanced Description
4Bid has emerged as one of the most active threat actors in recent years, targeting a broad array of sectors including government, defense, aerospace, energy, healthcare, manufacturing, logistics, education, and maritime. In late‑2025 and early‑2026, the group leveraged updated versions of its custom Rust‑based dropper to stage Blackout Locker, deploying it via an obfuscated .dat file written to %AppData% and renamed to .exe by cmd.exe. This technique is combined with a suite of backdoors – GoRed (Bulldog), ZeronetKit, BlackReaperRAT, Tuoni, Cobalt Strike, DEEPROOT, and others – which are installed either through spear‑phishing attachments or by exploiting zero‑day vulnerabilities such as ProxyShell in Microsoft Exchange and various misconfigurations in Veeam backup, WatchGuard, and Confluence. To maintain persistence and facilitate lateral movement the actors use legitimate remote‑access tools including AnyDesk, Panorama9 RMM, ScreenConnect and Splashtop, often bypassing or disabling endpoint protection via BYOVD drivers, signed malware, DLL sideloading, and reverse SSH tunnels. Credential theft is executed through DCSync, LSASS dumping with Mimikatz, and password spraying on VNC/SSH services, while exfiltration frequently occurs to C2 servers over DNS‑over‑HTTPS or encrypted channel protocols such as AES/ChaCha20. 4Bid’s recent operations also demonstrate a strategic shift toward monetization: ransomware campaigns such as Blackout Locker and ClearWater now accompany extensive surveillance via backdoors that collect system data, capture screens, harvest cloud credentials, and sabotage industrial control systems. The group has shown an ability to co‑operate with allied threat complexes (e.g., BO Team, Red Likho) by sharing infrastructure and targeting patterns, further amplifying their operational tempo. The actor’s use of both political motives—often framing attacks in a pro‑Ukrainian context—and clear financial incentives reflects a hybrid model that enables rapid escalation across borders while capitalizing on the high‑value targets within critical sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
4Bid operates with a high operational tempo, deploying campaigns every few weeks that blend ransomware dropper roll‑outs with persistent backdoor implantation. Victims range from small municipal utilities to large defense contractors; the group often exploits publicly known misconfigurations (Veeam CVEs, ProxyShell Exchange chain) before pivoting via Remote Desktop or RMM tools to maintain a foothold. 4Bid’s collaboration with other threat complexes such as the BO Team and Red Likho has enabled it to share infrastructure (e.g., GoRed, ZeronetKit backdoors) and coordinate dual‑phase attacks that first exfiltrate data before encrypting assets, thereby increasing leverage over high‑value targets.
IOC Patterns
Recommended Actions
Suggested Tags
Sources
Confidence Assessment
The analysis is based on multiple publicly available reports, threat‑intel feeds, and forensic observations that consistently identify the same tools, tactics, and indicators. The primary uncertainty lies in the precise attribution of all infrastructure elements to 4Bid versus its cooperating groups (BO Team, Red Likho). Additionally, some attack scenarios are inferred from overlapping capabilities rather than directly observed evidence, so operational details such as exact timing or full command sets remain partially speculative.
No campaigns linked yet.
No observed data linked yet.
62
Techniques
164
Tools
0
Campaigns
34
IOCs
0
Observed Data
14
Tactics