logo

BianLian Ransomware Spreads via Fake Invoice SVG Images in New Attacks

ID: 3341d198-936f-5c0e-9be4-b29dbe11991f

STIX ID: report--3341d198-936f-5c0e-9be4-b29dbe11991f

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

WatchGuard researchers identified a phishing campaign targeting Venezuelan companies that delivers BianLian-linked ransomware via malicious SVG image files which download a Go-built Windows payload. The campaign uses ja.cat link shortening and redirection through compromised Brazilian domains, performs environment checks (e.g., Wine, GODEBUG), and executes fast AES file encryption; researchers published multiple suspicious domains to monitor or block.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.