CISA says BianLian ransomware now focuses only on data theft
ID: 356f9908-8255-5e3e-92f2-97205cf5323e
STIX ID: report--356f9908-8255-5e3e-92f2-97205cf5323e
Feed Name: Bleeping Computer
The advisory reports that the BianLian ransomware operation has shifted to exclusively exfiltration-based extortion as of January 2024, using stolen RDP credentials, custom Go backdoors, commercial remote access tools, and Windows/ESXi targeting (including possible ProxyShell exploitation). Agencies (CISA/FBI/ACS) detail TTPs—Ngrok/Rsocks SOCKS5 tunneling, privilege-escalation (CVE-2022-37969), UPX packing, service renaming, webshells on Exchange, PowerShell compression, and victim-pressure tactics—and recommend restricting RDP, command-line/scripting, and PowerShell usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
