logo

New BianLian Ransomware Activity Detected: SVG Phishing Campaign Targeting Venezuelan Companies

ID: a9ab5d91-c613-5118-9559-7f4a9876a41c

STIX ID: report--a9ab5d91-c613-5118-9559-7f4a9876a41c

Feed Name: WatchGuard Secplicity Blog

Threat Score
72/100

Date Published: 2026-03-25

Date Updated: 2026-05-01

Author: Euler Neto

...
...

WatchGuard telemetry identified a phishing campaign distributing malicious SVG attachments in Spanish that, when opened, fetch a Go-based Windows executable linked to BianLian ransomware. The campaign leverages ja.cat shortened URLs and vulnerable redirector domains (Brazil-based) to host payloads, targets victims primarily in Venezuela (with earlier activity in Colombia), and uses anti-analysis techniques, Wine detection, AES assembly routines, and dynamic API loading; provided IoCs include several domains such as contabilidad.icu and documentodigital.cloud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.