Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: SHADOW-VOID-042, Storm-0978, Tropical Scorpius, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, RomCom, the Bulldog backdoor, defense-industry organizations, Smoke Sandstorm, TA455, Yellow Liderc, Tortoiseshell, aviation, defense industries, LuoYu, foreign entities, Qilin, file transfer tools, APT35, Imperial Kitten, Blue Echidna, UNC2596, GOFFEE, Fluffy Wolf, CASCADE PANDA

Description

4bid has emerged as one of the most active threat actors in recent years, targeting a broad array of sectors including government, defense, aerospace, energy, healthcare, manufacturing, logistics, education and maritime. In late‑2025 and early‑2026 the group leveraged updated versions of its custom Rust‑based dropper to stage Blackout Locker, deploying it via an obfuscated .dat file written to user AppData and renamed to .exe by cmd.exe. This technique is combined with a suite of backdoors – GoRed (Bulldog), ZeronetKit, BlackReaperRAT, Tuoni, Cobalt Strike, DEEPROOT and others – which are installed either through spear‑phishing attachments or by exploiting zero‑day vulnerabilities such as ProxyShell in Microsoft Exchange and various misconfigurations in Veeam backup, WatchGuard and Confluence. To maintain persistence and facilitate lateral movement the actors use legitimate remote‑access tools including AnyDesk, Panorama9 RMM, ScreenConnect and Splashtop, often bypassing or disabling endpoint protection via BYOVD drivers, signed malware, DLL sideloading, and reverse SSH tunnels. Credential theft is executed through DCSync, LSASS dumping with Mimikatz, and password spraying on VNC/SSH services, while exfiltration frequently occurs to C2 servers over DNS‑over‑HTTPS or encrypted channel protocols such as AES/ChaCha20. 4bid’s recent operations also demonstrate a strategic shift toward monetization: ransomware campaigns such as Blackout Locker and ClearWater now accompany extensive surveillance via backdoors that collect system data, capture screens, harvest cloud credentials, and sabotage industrial control systems. The group has shown an ability to co‑operate with allied threat complexes (e.g., BO Team, Red Likho) by sharing infrastructure and targeting patterns, further amplifying their operational tempo. The actor’s use of both political motives—often framing attacks in a pro-Ukrainian context—and clear financial incentives reflects a hybrid model that enables rapid escalation across borders while capitalizing on the high-value targets within critical sectors.

Goals & Targeting

Targeted Sectors

Healthcare
Government
Manufacturing
Aerospace
Financial services
Transportation
Defense
Energy
Critical infrastructure
Food agriculture
Pharmaceutical
Chemical
Retail
Education
Construction
Telecommunications
Media
Utilities
Aviation
Maritime
Oil gas
Information technology
Entertainment

Targeted Countries / Regions

Belarus
Egypt
Kazakhstan
Russian Federation
Syrian Arab Republic
United Arab Emirates
RU
CN
US
AE
BR
EG
SY
KZ
BY
UA
IL
IR
TW
FR
CA
GB
DE
IN
MX
SA

AI Analysis

Grounded in web research
· analyzed in 23 chunks · 6 days ago

Executive Summary

4Bid is a financial‑driven threat actor that blends ransomware, persistent RAT deployments, and industrial sabotage to monetize high‑value targets across government, defense, energy, and critical infrastructure worldwide. Leveraging a Rust‑based dropper, the group stages Blackout Locker or ClearWater while installing backdoors such as AnyDesk, GoRed, and ZeronetKit for long‑term persistence and lateral movement. 4Bid’s hybrid profile—combining spear‑phishing, zero‑day exploitation, and legitimate remote‑access tools—enables rapid escalation across borders.

Goals & Targeting

4Bid pursues dual objectives: first, to extract monetary gain through ransomware and extortion; second, to conduct espionage and sabotage against strategic industries. The actor’s targeting profile focuses on both public utilities (energy, water, airports) and private sectors (defense contractors, aerospace, finance), leveraging insider‑like access conferred by remote‑access tools and exploited misconfigurations. By combining ransomware shock value with stealthy persistence via RATs and distributed infrastructure, 4Bid seeks to maintain long‑term footholds in high‑value environments while expanding reach into new geographic markets such as the UAE, Kazakhstan, Syria, and Egypt.

Enhanced Description

4Bid has emerged as one of the most active threat actors in recent years, targeting a broad array of sectors including government, defense, aerospace, energy, healthcare, manufacturing, logistics, education, and maritime. In late‑2025 and early‑2026, the group leveraged updated versions of its custom Rust‑based dropper to stage Blackout Locker, deploying it via an obfuscated .dat file written to %AppData% and renamed to .exe by cmd.exe. This technique is combined with a suite of backdoors – GoRed (Bulldog), ZeronetKit, BlackReaperRAT, Tuoni, Cobalt Strike, DEEPROOT, and others – which are installed either through spear‑phishing attachments or by exploiting zero‑day vulnerabilities such as ProxyShell in Microsoft Exchange and various misconfigurations in Veeam backup, WatchGuard, and Confluence. To maintain persistence and facilitate lateral movement the actors use legitimate remote‑access tools including AnyDesk, Panorama9 RMM, ScreenConnect and Splashtop, often bypassing or disabling endpoint protection via BYOVD drivers, signed malware, DLL sideloading, and reverse SSH tunnels. Credential theft is executed through DCSync, LSASS dumping with Mimikatz, and password spraying on VNC/SSH services, while exfiltration frequently occurs to C2 servers over DNS‑over‑HTTPS or encrypted channel protocols such as AES/ChaCha20. 4Bid’s recent operations also demonstrate a strategic shift toward monetization: ransomware campaigns such as Blackout Locker and ClearWater now accompany extensive surveillance via backdoors that collect system data, capture screens, harvest cloud credentials, and sabotage industrial control systems. The group has shown an ability to co‑operate with allied threat complexes (e.g., BO Team, Red Likho) by sharing infrastructure and targeting patterns, further amplifying their operational tempo. The actor’s use of both political motives—often framing attacks in a pro‑Ukrainian context—and clear financial incentives reflects a hybrid model that enables rapid escalation across borders while capitalizing on the high‑value targets within critical sectors.

Key Capabilities

  • Custom script-based discovery of installed remote‑desktop and security solutions
  • Use of patched Process Explorer to download and deploy additional malware such as Tuoni or Cobalt Strike
  • Deployment of ransomware (Blackout Locker, ClearWater) for impact
  • Installation and operation of RATs (BlackReaperRAT, Panorama9 RMM, AnyDesk, Dev Tunnels) to maintain persistence and lateral movement
  • Use a Rust‑written dropper to distribute Blackout Locker
  • Writes the ransomware payload to %AppData%\Local\…\.dat before swapping its extension to .exe via Windows command prompt
  • Checks for administrative privileges before execution
  • Installs and configures AnyDesk remote‑access software with unattended access credentials
  • Downloads additional remote management tools such as Panorama9 RMM and Dev Tunnels via scripts
  • Exfiltrates collected information to an external C2 server at 185.221.153[.]121
  • Uses reverse SSH tunnels for command-and-control and persistence
  • Dormant backdoors designed to survive detection and reappear later
  • Credential theft via AD DCSync operations using a modified DCSYNCER.SLICK tool
  • Screen capture and fake login prompts to elevate privileges and exfiltrate data
  • Signing binaries with legitimate code‑signing certificates for weaponization
  • Spear phishing with malicious attachments or links
  • DLL sideloading/hijacking to execute payloads
  • Use of webDAV for file transfer or C2
  • PowerShell execution bypassing policies
  • Telegram for communication and C2
  • Distributed denial of service (DDoS) operations targeting SCADA networks
  • Exploitation of unmanaged assets in industrial environments

MITRE ATT&CK Tactics

Discovery
Execution
Persistence
Defense Evasion
Impact
Initial Access
Command and Control
Exfiltration
Privilege Escalation
Credential Access
Collection
Remote Services
Lateral Movement

ATT&CK Techniques

T1018
T1076
T1105
T1059
T1486
T1036.015
T1059.003
T1041
T1059.004
T1566
T1574.009
T1113
T1003.006
T1090
T1036
T1110
T1046
T1059.001
T1021.004
T1074
T1053.005
T1484.002
T1190
T1040
T1104
T1043
T1546.003
T1498.004
T1068
T1078
T1027
T1204
T1552
T1566.001
T1086
T1106
T1071.001
T1566.002
T1055
T1574.003
T1070
T1098
T1003
T1574.004
T1003.002
T1578.001
T1195
T1574.001
T1059.007
T1071.004
T1064
T1053
T1547
T1204.001
T1070.002
T1021
T1498.001
T1081
T1515
T1136.001
T1003.001

Software / Tooling

Blackout Locker
ClearWater
BlackReaperRAT
Panorama9 RMM
AnyDesk
Dev Tunnels
GoRed
ZeronetKit
Tuoni
Cobalt Strike
patched Process Explorer
ADRecon
Advanced IP Scanner
Babuk
BloodHound
Chaos
Chisel
CloudFlared
Cobint
CrackMapExec
Endurance-Wiper
FaceFish
Fscan
GOST
Impacket
LockBit 3.0
Mimikatz
ngrok
NSSM
PEASS
PowerView
ProcDump
PsExec
PuTTY
RClone
RemCom
Revsocks
XenAllPasswordPro
grabff
Warp RAT
DEEPROOT
DCSYNCER.SLICK
GHOSTLINE
POLLBLEND
TWOSTROKE
Rust dropper
Nmap
OPENVAS
Telegram
Sharp7Extend
Broadside (Mirai variant)
ZEROLOT
Sting
SocGholish
Mythic agent
VIPERTUNNEL
PowerShell scripts
JavaScript payloads
Malicious downloaders
GoRed (Bulldog)
Red Likho
VBShower
CloudAtlas backdoor
PowerShower PS script
VBCloud VBS files
FileGrabber
PasswordStealer
InfoCollector
Custom Python credential extraction script
EchoGather
PureCrypter
PureHVNC/PureRAT
PureLogs Stealer
Pay2Key
Notepad++
WinMerge
TightVNC Viewer
MuPDF
ScoringMathTea
Comebacker
VAX‑One
Fooder
MuddyViper
DCSyncer
Imperial Kitten
MuddyWater
GalaxyGato
C5 backdoor
ConfuserEx
SQLMap
Neursite
NeuralExecutor
EdgeStepper
LittleDaemon
DaemonicLogistics
SlowStepper
WinDealer
SpyDealer
BadAudio
CalaRat
BLOODALCHEMY
kidsRAT
RustVoralix
BRICKSTORM
Junction
GuestConduit
PhantomVAI loader
Katz Stealer
AsyncRAT
XWorm
FormBook
DCRat
ScreenConnect
Splashtop Remote (SRManager.exe)
Atera RMM platform
PuTTY SSH client
COROXY backdoor
Agenda ransomware binary
Windows Subsystem for Linux (WSL)
SimpleHelp
PDQ Connect
Fleetdeck
N‑able
LogMeIn Resolve
Impacket wmiexec.py
VBScript
nltest
Megazord
Broadside Botnet
GTG-1002 Malware
Anthropic Claude LLM
Warlock
LockBit
Velociraptor
Visual Studio Code
Cloudflare Workers
Set-Alias
Export-Alias

Campaigns & Victims

4Bid operates with a high operational tempo, deploying campaigns every few weeks that blend ransomware dropper roll‑outs with persistent backdoor implantation. Victims range from small municipal utilities to large defense contractors; the group often exploits publicly known misconfigurations (Veeam CVEs, ProxyShell Exchange chain) before pivoting via Remote Desktop or RMM tools to maintain a foothold. 4Bid’s collaboration with other threat complexes such as the BO Team and Red Likho has enabled it to share infrastructure (e.g., GoRed, ZeronetKit backdoors) and coordinate dual‑phase attacks that first exfiltrate data before encrypting assets, thereby increasing leverage over high‑value targets.

IOC Patterns

  • Writes executable to %AppData%\Local path and changes extension via cmd shell
  • File extension masquerading (.dat→.exe)
  • Deploys Rust‑compiled binary dropper
  • IP 185.221.153[.]121
  • anydesk.exe file name
  • Unattended AnyDesk ID usage
  • malicious file path in %USERPROFILE%\AppData\Local with .dat then renamed to .exe
  • DLL hijacking via manipulated search order
  • Reverse SSH tunneling for hidden command channels
  • Malicious binaries signed with valid code‑signing certificates
  • Spear phishing emails attachments or links
  • WebDAV file transfer strings
  • PowerShell execution bypassing policies
  • VNC brute‑force on default credentials
  • Telegram C2 IDs used
  • Presence of backdoors GoRed and ZeronetKit
  • DNS hijacking/redirect implants
  • Software update spoofing via fake updater servers
  • PLC communication disruption through malicious code
  • CVE exploitation – ProxyShell Exchange chain, Veeam CVEs, WatchGuard CVE-2022‑26318, Confluence CVE‑2017‑11882, etc.
  • Web shell uploads (.aspx) to Exchange root
  • Obfuscated command strings for GoRed download
  • Use of .live and .fr domain TLDs in file uploads
  • CVE-2017-11882 RTF exploit leading to VBShower download
  • Malicious LNK files
  • Bait PDF files embedded in archives

Recommended Actions

  • Monitor for unfamiliar .dat files created under %AppData%\Local that are later renamed to .exe
  • Block outbound traffic to IP 185.221.153[.]121 and other known malicious addresses
  • Detect and block installation of AnyDesk, Panorama9 RMM, DevTunnels, or other RMM tools from untrusted sources
  • Enable alerts on DLL sideloading or search‑order hijacking attempts
  • Deploy EDR rules for reverse SSH tunnels and dormant backdoor persistence
  • Enforce MFA on AD accounts and restrict DCSync usage
  • Patch all known CVEs in Veeam, Exchange ProxyShell chain, WatchGuard, Confluence, and other exposed services
  • Educate users about spear‑phishing with malicious attachments or links
  • Implement application whitelisting to prevent unauthorized installation of remote‑access software
  • Segment OT networks from IT networks and monitor for anomalous traffic such as DNS hijacking or PLC command tampering
  • Apply code‑signing validation for all downloaded binaries
  • Use network detection for obfuscated PowerShell activity and encrypted C2 channels (AES/ChaChA20)

Suggested Tags

ransomware
hacktivist
remote-desktop tool
RAT
persistent access
TA569
APT44
Blackout Locker
Rust dropper
masquerading
command shell
geographical spread
BO Team
4BID
AnyDesk
BlackReaperRAT
ClearWater Ransomware
Panorama9 RMM
Dev Tunnels
Industrial Targeting
Remote Access Tool
AnyDesk RMM
Exfiltration IP
Warp RAT
APT4BID
Spear_Phishing
DLL_Sideloading
Backdoor_Dropper
Reverse_SSH
Credential_Thief_DCSync
Screen_Capture
Code_Signing_Reuse
Rust_Malware
Telegram C2
SCADA attack
VNC brute force
WebDAV exploitation
DDoS
Industrial Control System target
Russian-speaking threat actor
PoliticalMotivation
Russia EU
US Cyberwarfare

Confidence Assessment

The analysis is based on multiple publicly available reports, threat‑intel feeds, and forensic observations that consistently identify the same tools, tactics, and indicators. The primary uncertainty lies in the precise attribution of all infrastructure elements to 4Bid versus its cooperating groups (BO Team, Red Likho). Additionally, some attack scenarios are inferred from overlapping capabilities rather than directly observed evidence, so operational details such as exact timing or full command sets remain partially speculative.

ATT&CK Techniques

Exfiltration
1 technique
Lateral Movement
2 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 10 Filename 7 MD5 Hash 1 IPv4 Address 2

References

  1. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  2. learn.microsoft.com — Cited by web research for: Microsoft.PowerShell.Commands.SetAliasCommand

Intel Summary

62

Techniques

164

Tools

0

Campaigns

34

IOCs

0

Observed Data

14

Tactics

Tags

Ransomware
APT
Backdoor / C2
DDoS
Hacktivism
ransomware
DLL side-loading
hacktivism
Geopolitical Espionage
Financial Motivation
RAT
Industrial Targeting
credential theft
hacktivist
backdoor
pro-ukrainian
cross-border attacks
backdoor malware
remote access tool
4bid
Blackout Locker
rust-based dropper
command shell abuse
file staging
industrial control system
collaboration with other threat groups
AnyDesk exploitation
signed malware
reverse SSH
RDP/RMM exploitation
ClearWater ransomware
VNC exploitation
password spraying
DDoS attack
SCADA targeting
industrial control
OT security
DNS hijacking
Mirai botnet
Qilin ransomware
Cyber-Physical
Logistics Target
Data Wiping
scheduled task
vulnerability exploitation
misconfiguration
credential abuse
network sniffing
PostgreSQL exploit
malicious RTF
PowerShell attacks
spear phishing
industrial espionage
masquerading
Telegram C2
remote-desktop tool
persistent access
TA569
APT44
Rust dropper
command shell
geographical spread
BO Team
4BID
AnyDesk
BlackReaperRAT
ClearWater Ransomware
Panorama9 RMM
Dev Tunnels
Remote Access Tool
AnyDesk RMM
Exfiltration IP
Warp RAT
APT4BID
Spear_Phishing
DLL_Sideloading
Backdoor_Dropper
Reverse_SSH
Credential_Thief_DCSync
Screen_Capture
Code_Signing_Reuse
Rust_Malware
SCADA attack
VNC brute force
WebDAV exploitation
Industrial Control System target
Russian-speaking threat actor
PoliticalMotivation
Russia EU
US Cyberwarfare

Details

MITRE ID
APT35
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.