Ransomware, written in .NET.
Objectives
Executive Summary
Solidbit is a medium-sophistication criminal threat actor primarily involved in ransomware activities, with a focus on financial gain through extortion. The group has been active since at least 2019 and is known for targeting multiple sectors and geographies, delivering .NET-based ransomware via phishing campaigns.
Goals & Targeting
Solidbit's main goals are generating income through ransomware extortions, disrupting business operations, and achieving notoriety within the cybercrime community. The group targets various sectors including healthcare and education, as well as multiple countries with less robust cybersecurity frameworks, making attacks more feasible and profitable.
Enhanced Description
Solidbit operates as a cybercriminal entity specializing in ransomware operations. Their primary modus operandi involves distributing .NET-based malware through spear-phishing emails containing malicious links or attachments. The group targets diverse industries but has notably focused on sectors like healthcare and education due to their vulnerability and high ransom potential. Solidbit's activities disrupt businesses globally, causing significant financial losses and reputational damage. Their operations are characterized by a blend of technical proficiency and strategic targeting, enabling them to evade detection and persist in the threat landscape.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Solidbit engages in active campaigns, often varying in intensity. Their targets include mid-sized to large organizations across different countries. Campaigns are region-specific but not limited geographically.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is strong confidence in the assessment of Solidbit's ransomware activities. However, gaps remain regarding exact geographic origins and specifics of campaign methodologies.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics