Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Warning Issued About BianLian Ransomware Attacks By CISA & FBI
News & Analysis Attacks Ransomware

Warning Issued About BianLian Ransomware Attacks By CISA & FBI

Olivia WilliamBy Olivia WilliamMay 17, 2023Updated:August 20, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Warning Issued About BianLian Ransomware Attacks By CISA & FBI
Warning Issued About BianLian Ransomware Attacks By CISA & FBI
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

CISA & FBI has released a joint Cybersecurity Advisory from government agencies in the United States and Australia to warn businesses about the most recent tactics, methods, and procedures (TTPs) utilized by the BianLian ransomware group.

Since June 2022, BianLian, a ransomware and data extortion outfit, has been aiming its attacks towards organizations within the United States and Australia’s critical infrastructure.

FBI confirms BianLian ransomware switch to extortion only attacks – The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Australian Cyber Security Centre (ACSC) have published a joint advisory to inform … https://t.co/idtojLrfux

— G & R Computers (@GRComputers) May 17, 2023

The #StopRansomware alert is based on findings from the FBI and the Australian Cyber Security Centre as of March 2023 and is part of a larger effort to combat ransomware. The goal is to arm defenders with the knowledge they need to defend themselves against BianLian and other malware better.

After collecting sensitive information from target networks, BianLian encrypted systems and threatened to release the files as a second form of extortion.

As a result of Avast’s publication of a decryptor for the ransomware in January 2023, the group has shifted its focus to extortion via data theft without encrypting systems. Since these instances are effectively data breaches, they also cause the victim’s reputation to suffer, erode the trust of their customers, and open them up to legal issues.

According to the CISA advice, BianLian compromises systems with legitimate Remote Desktop Protocol (RDP) credentials that were likely obtained through phishing or were purchased through early access brokers.

BianLian then does network reconnaissance using a bespoke Go backdoor, commercial remote access tools, the command line, and scripts. The final step is the exfiltration of victim data using a file sharing service like Mega, the Rclone tool, or the File Transfer Protocol (FTP).

BianLian uses PowerShell and the Windows Command Shell to stop antivirus-related tasks from executing and dodge detection. Tamper protection in Sophos security systems is also disabled by manipulating the Windows Registry.

Restricting the usage of PowerShell on mission-critical systems, prohibiting command-line and scripting activities, and limiting the use of remote desktop protocols are all recommended mitigations.

Several preventative steps are suggested in the warning to keep the network secure:

  • Make sure all applications and tools used for remote access are being monitored and controlled.
  • Implement severe security measures and limit access to remote desktop programs like RDP.
  • Reduce your reliance on PowerShell, get the newest version, and turn on detailed logging.
  • Use the concept of least privilege and conduct regular audits of administrative accounts.
  • Create a backup plan that includes numerous, off-site copies of your data.
  • Password policies should be in line with NIST recommendations for security, including in terms of length, storage, reuse, and multi-factor authentication.
  • Software and firmware updates should be performed routinely, networks should be segmented to increase security, and network activity should be actively monitored.

Full bulletins from CISA and the ACSC provide more information on the recommended countermeasures, indicators of compromise (IoCs), command traces, and BianLian approaches.

Conclusion

The FBI, CISA, and ACSC are warning critical infrastructure organizations of BianLian ransomware assaults. Since June 2022, the gang has used remote desktop protocol (RDP) credentials from initial access brokers or phishing assaults to access victim networks. CISA, FBI, and ACSC claim the BianLian gang has targeted US critical infrastructure organizations and Australian private companies, including a critical infrastructure organization, for a year. Starting in January 2023, the organization focused on data exfiltration rather than ransomware.

After getting network access, the gang installs remote management and access tools including Atera Agent, AnyDesk, SplashTop, and TeamViewer plus a victim-specific Go-based backdoor. BianLian also created administrator accounts, changed passwords, disabled antivirus software, and modified Windows registry to disable and uninstall Sophos endpoint protection solutions. Advanced Port Scanner, SoftPerfect Network Scanner, SharpShares, PingCastle, Impacket, and command-line scripting are used for reconnaissance.

Olivia William
  • Olivia William
    Ciso Playbook: Cyber Resilience Strategy
  • Olivia William
    Apple Responds Swiftly to Active Security Threats with iOS 16.5.1 Update
  • Olivia William
    Zacks Investment Research Faces Larger Data Breach Affecting 8.8 Million Users
  • Olivia William
    British Airways and Boots Battling Data Breaches, Millions of Customers Affected

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}