Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors solidbit

Description

Ransomware, written in .NET.

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Solidbit is a medium-sophistication criminal threat actor primarily involved in ransomware activities, with a focus on financial gain through extortion. The group has been active since at least 2019 and is known for targeting multiple sectors and geographies, delivering .NET-based ransomware via phishing campaigns.

Goals & Targeting

Solidbit's main goals are generating income through ransomware extortions, disrupting business operations, and achieving notoriety within the cybercrime community. The group targets various sectors including healthcare and education, as well as multiple countries with less robust cybersecurity frameworks, making attacks more feasible and profitable.

Enhanced Description

Solidbit operates as a cybercriminal entity specializing in ransomware operations. Their primary modus operandi involves distributing .NET-based malware through spear-phishing emails containing malicious links or attachments. The group targets diverse industries but has notably focused on sectors like healthcare and education due to their vulnerability and high ransom potential. Solidbit's activities disrupt businesses globally, causing significant financial losses and reputational damage. Their operations are characterized by a blend of technical proficiency and strategic targeting, enabling them to evade detection and persist in the threat landscape.

Key Capabilities

  • Develops and deploys .NET-based ransomware
  • Uses exploit kits for initial access
  • Maintains command-and-control infrastructure for communication

MITRE ATT&CK Tactics

Initial Access
Exfiltration
Credential Access

ATT&CK Techniques

T1566.001
T1074

Software / Tooling

Solidbit Ransomware
Phishing Kits

Campaigns & Victims

Solidbit engages in active campaigns, often varying in intensity. Their targets include mid-sized to large organizations across different countries. Campaigns are region-specific but not limited geographically.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • C2 infrastructure using encrypted communication channels

Recommended Actions

  • Enhance email filtering and threat detection
  • Implement multi-factor authentication for critical accounts
  • Conduct regular data backups and verify their integrity

Suggested Tags

ransomware
cybercrime
financial-gain

Confidence Assessment

There is strong confidence in the assessment of Solidbit's ransomware activities. However, gaps remain regarding exact geographic origins and specifics of campaign methodologies.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
cybercrime
financial-gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.