A new SolidBit ransomware variant has been distributed through fraudulent applications aimed at gamers and social media users, including fake League of Legends account checker, Social Hacker, and Instagram Follower Bot tools hosted on GitHub. Trend Micro reported that the lures execute PowerShell to weaken parts of Windows Defender, drop additional executables, and then deploy the ransomware payload, expanding the group’s reach beyond traditional enterprise intrusion methods.
The payload is a .NET binary that uses obfuscation, anti-debugging techniques, persistence through the Windows Run registry key, AES-256 encryption, shadow copy deletion, service termination, and ransom note deployment. Researchers said the malware appears to be a rebranded Yashma/Chaos-derived strain rather than a genuine LockBit variant, despite similarities in presentation, and noted that the operators were promoting a ransomware-as-a-service model on underground forums with affiliates offered 80% of ransom payments.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
On August 2, 2022, Trend Micro researchers analyzed a new SolidBit ransomware variant distributed via fake GitHub-hosted tools such as a League of Legends account checker, Social Hacker, and Instagram Follower Bot. The report said the malware disabled parts of Windows Defender, deployed the ransomware payload, and was likely a Yashma/Chaos-derived strain rather than a true LockBit variant.
A researcher found that the SolidBit group posted an underground forum advertisement on June 29 seeking ransomware-as-a-service affiliates and offering them 80% of ransom payments. This indicated the group's move to expand through an affiliate model.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.