logo

CISA says BianLian ransomware now focuses only on data theft

ID: 356f9908-8255-5e3e-92f2-97205cf5323e

STIX ID: report--356f9908-8255-5e3e-92f2-97205cf5323e

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-11-21

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

The advisory reports that the BianLian ransomware operation has shifted to exclusively exfiltration-based extortion as of January 2024, using stolen RDP credentials, custom Go backdoors, commercial remote access tools, and Windows/ESXi targeting (including possible ProxyShell exploitation). Agencies (CISA/FBI/ACS) detail TTPs—Ngrok/Rsocks SOCKS5 tunneling, privilege-escalation (CVE-2022-37969), UPX packing, service renaming, webshells on Exchange, PowerShell compression, and victim-pressure tactics—and recommend restricting RDP, command-line/scripting, and PowerShell usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.