#StopRansomware: BianLian Ransomware Group
ID: b2d4c619-4ee2-5d67-a738-13da643ea90c
STIX ID: report--b2d4c619-4ee2-5d67-a738-13da643ea90c
Feed Name: ASD's ACSC - Advisories RSS
Date Published: 2024-11-21
Date Updated: 2026-07-24
Author: Australian Cyber Security Centre (ACSC)
## Executive summary FBI, CISA, and ASD's ACSC released a joint advisory on the BianLian ransomware and data extortion group, detailing observed tactics (RDP/valid-accounts, ProxyShell exploitation), custom Go backdoors, credential harvesting (LSASS, NTDS), exfiltration methods (Rclone, FTP, Mega), sample ransom notes, and IOCs (file hashes). The advisory notes a shift from double-extortion with encryption to primarily exfiltration-based extortion, impacts to multiple U.S. and Australian critical infrastructure and private sectors, and provides mitigations and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
