CISA says BianLian ransomware now focuses only on data theft

Teilen:

The BianLian ransomware operation has shifted its tactics, becoming primarily a data theft extortion group, according to an updated advisory from the U.S. Cybersecurity & Infrastructure Security Agency, the FBI, and the Australian Cyber Security Centre.

This new information comes in an update to a joint advisory released in May by the same agencies, which warned about BianLian’s shifting tactics involving the use of stolen Remote Desktop Protocol (RDP) credentials, custom Go-based backdoors, commercial remote access tools, and targeted Windows Registry modifications.

At the time, BianLian had started a switch to data theft extortion, gradually abandoning file encryption tactics, especially after Avast released a decryptor for the family in January 2023.

While BleepingComputer knows of BianLian attacks using encryption towards the end of 2023, the updated advisory says the threat group having shifted exclusively to data extortion since January 2024.

“BianLian group originally employed a double-extortion model in which they encrypted victims’ systems after exfiltrating the data; however, they shifted primarily to exfiltration-based extortion around January 2023 and shifted to exclusively exfiltration-based extortion around January 2024,” reads CISA’s updated advisory.

Another point highlighted in the advisory is that BianLian now attempts to obscure their origin by using foreign-language names. However, the intelligence agencies are confident the primary operators and multiple affiliates are based in Russia.

The advisory has also been updated with the ransomware gang’s new techniques, tactics, and procedures:

  • Targets Windows and ESXi infrastructure, possibly the ProxyShell exploit chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) for initial access.
  • Uses Ngrok and modified Rsocks to mask traffic destinations using SOCK5 tunnels.
  • Exploits CVE-2022-37969 to escalate privileges on Windows 10 and 11.
  • Uses UPX packing to bypass detection.
  • Renames binaries and tasks after legitimate Windows services and security products for evasion.
  • Creates Domain Admin and Azure AD Accounts, performs network login connections via SMB, and installs webshells on Exchange servers.
  • Users PowerShell scripts to compress collected data before exfiltration.
  • Includes new Tox ID for victim communication in ransom note.
  • Prints ransom notes on printers connected to the compromised network and calls employees of the victim companies to apply pressure.

Based on the above, CISA recommends strictly limiting the use of RDP, disabling command-line and scripting permissions, and restricting the use of PowerShell on Windows systems.

BianLian’s latest activity

Active since 2022, BianLian ransomware has had a prolific year so far, listing 154 victims on its extortion portal on the dark web.

Though most of the victims are small to medium-sized organizations, BianLian has had some notable breaches recently, including those against Air Canada, Northern Minerals, and the Boston Children’s Health Physicians.

The threat group has also recently announced breaches against a global Japanese sportswear manufacturer, a prominent Texas clinic, a global mining group, an international financial advisory, and a major dermatology practice in the U.S., but those have not been confirmed yet.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:47 pm, Juli 4, 2025
Wetter-Symbol 24°C
L: 23° | H: 26°
overcast clouds
Luftfeuchtigkeit: 41 %
Druck: 1026 mb
Wind: 9 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 89%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:19 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
23° | 26°°C 0 mm 0% 13 mph 42 % 1026 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 19°°C 0.97 mm 97% 13 mph 90 % 1021 mb 0 mm/h
So. Juli 06 10:00 pm
Wetter-Symbol
16° | 20°°C 1 mm 100% 10 mph 89 % 1010 mb 0 mm/h
Mo. Juli 07 10:00 pm
Wetter-Symbol
14° | 23°°C 1 mm 100% 13 mph 77 % 1016 mb 0 mm/h
Di. Juli 08 10:00 pm
Wetter-Symbol
13° | 25°°C 0 mm 0% 9 mph 77 % 1020 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 9 mph 42 % 1026 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
24° | 25°°C 0 mm 0% 12 mph 37 % 1025 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 13 mph 31 % 1023 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 10 mph 40 % 1022 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 10 mph 50 % 1021 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 52 % 1019 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
14° | 14°°C 0.97 mm 97% 9 mph 90 % 1018 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
17° | 17°°C 0.7 mm 70% 10 mph 82 % 1017 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,668.34
-0.56%
Ethereum(ETH)
€2,169.87
-1.49%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.90
-2.56%
Solana(SOL)
€127.90
-2.58%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.141759
-3.79%
Shiba Inu(SHIB)
€0.000010
-2.90%
Pepe(PEPE)
€0.000008
-5.78%
Nach oben scrollen