New BianLian Ransomware Activity Detected: SVG Phishing Campaign Targeting Venezuelan Companies
ID: a9ab5d91-c613-5118-9559-7f4a9876a41c
STIX ID: report--a9ab5d91-c613-5118-9559-7f4a9876a41c
Feed Name: WatchGuard Secplicity Blog
WatchGuard telemetry identified a phishing campaign distributing malicious SVG attachments in Spanish that, when opened, fetch a Go-based Windows executable linked to BianLian ransomware. The campaign leverages ja.cat shortened URLs and vulnerable redirector domains (Brazil-based) to host payloads, targets victims primarily in Venezuela (with earlier activity in Colombia), and uses anti-analysis techniques, Wine detection, AES assembly routines, and dynamic API loading; provided IoCs include several domains such as contabilidad.icu and documentodigital.cloud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
