BianLian Ransomware Spreads via Fake Invoice SVG Images in New Attacks
ID: 3341d198-936f-5c0e-9be4-b29dbe11991f
STIX ID: report--3341d198-936f-5c0e-9be4-b29dbe11991f
Feed Name: HackRead
Threat Score
WatchGuard researchers identified a phishing campaign targeting Venezuelan companies that delivers BianLian-linked ransomware via malicious SVG image files which download a Go-built Windows payload. The campaign uses ja.cat link shortening and redirection through compromised Brazilian domains, performs environment checks (e.g., Wine, GODEBUG), and executes fast AES file encryption; researchers published multiple suspicious domains to monitor or block.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
