Cyber Security News

SolidBit Ransomware Targets Gamers and Social Media Users with New Variant

Experts from Trend Micro analyzed a pattern of a new SolidBit Ransomware variant that aims at gamers and social media platforms. According to the reports, this malware was uploaded to GitHub, where it is masquerading as different applications like a League of Legends accounts checker tool and an Instagram follower bot, to lure in victims. 

SolidBit Ransomware Masquerading As Different Applications

This new version of ‘SolidBit ransomware’ is a.NET compiled binary. It is believed of being like a ‘LockBit ransomware’, as both share similarities in their chat support sites’ formatting and the file names of their ransom note.

SolidBit ransomware variant masquerading as a League of Legends account checker tool on GitHub

The researchers explain saying the League of Legends account checker on GitHub is packed with a file and instructions on how to use the tool but no GUI (Graphical User Interface).

“When an unsuspecting victim runs the application, it automatically executes malicious PowerShell codes that drop the ransomware. Another file that comes with the ransomware is named “Source code,” but this seems to be different from the compiled binary”, Trend Micro researchers.

Details about the fraudulent League of Legends account checker

Additionally experts noticed an executable file named Rust LoL Accounts Checker.exe protected by Safengine Shielden, which obfuscates samples and applications to make reverse engineering and analysis harder. On the execution of the file, an error window appears that debugging tools have been spotted.

Upon clicking this executable file, it will drop and execute Lol Checker x64.exe, which runs the malicious PowerShell codes that drop and execute the ‘SolidBit Ransomware’. Further, this file disables the Windows Defender’s scheduled scans by using PowerShell command. Finally, the file will drop and execute the file Runtime64.exe, called ‘SolidBit ransomware’.

Pop-up window that SolidBit ransomware shows on the victim’s screen

Analysis says the SolidBit Ransomware targets social media users and is utilized for ransomware-as-a-service (RaaS) activities. Therefore to mitigate the risk, organizations can implement ‘Trend Micro Vision One, which has multilayered protection and behavior detection capabilities. ‘Trend Micro Apex One’ also provides next-level automated threat detection and response to protect endpoints against advanced issues, like fileless threats and ransomware.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago