BianLian Ransomware Exploits RDP Credentials for Initial Access
ID: 44bdb36a-5954-5ed1-9f2f-41182df5bfec
STIX ID: report--44bdb36a-5954-5ed1-9f2f-41182df5bfec
Feed Name: Cyber Press
**Executive Summary:** BianLian is an active, prolific ransomware group that has shifted from pure encryption to double-extortion, exploiting RDP credentials and notable vulnerabilities (ProxyShell, SonicWall) while using custom Go-based backdoors and TLS-encrypted C2 infrastructure with identifiable certificate patterns; it targets high-value sectors (notably legal and healthcare) and provides huntable IoCs such as unique Go libraries, certificate subject/issuer patterns, ports, and ASNs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
