US-CERT- #StopRansomware: BianLian Ransomware Group

Started by Netwörkheäd, May 24, 2023, 06:04:49 PM

Previous topic - Next topic

Netwörkheäd

#StopRansomware: BianLian Ransomware Group

[html]

Summary


Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit https://www.cisa.gov/stopransomware">stopransomware.gov to see all #StopRansomware advisories and learn more about other ransomware threats and no-cost resources.


The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Australian Cyber Security Centre (ACSC) are releasing this joint Cybersecurity Advisory to disseminate known BianLian ransomware and data extortion group IOCs and TTPs identified through FBI and ACSC investigations as of March 2023.





Actions to take today to mitigate cyber threats from BianLian ransomware and data extortion:

         • Strictly limit the use of RDP and other remote desktop services.

         • Disable command-line and scripting activities and permissions.

         • Restrict usage of PowerShell and update Windows PowerShell or PowerShell Core to the latest version.



BianLian is a ransomware developer, deployer, and data extortion cybercriminal group that has targeted organizations in multiple U.S. critical infrastructure sectors since June 2022. They have also targeted Australian critical infrastructure sectors in addition to professional services and property development. The group gains access to victim systems through valid Remote Desktop Protocol (RDP) credentials, uses open-source tools and command-line scripting for discovery and credential harvesting, and exfiltrates victim data via File Transfer Protocol (FTP), Rclone, or Mega. BianLian group actors then extort money by threatening to release data if payment is not made. BianLian group originally employed a double-extortion model in which they encrypted victims' systems after exfiltrating the data; however, around January 2023, they shifted to primarily exfiltration-based extortion.


FBI, CISA, and ACSC encourage critical infrastructure organizations and small- and medium-sized organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of BianLian and other ransomware incidents.


Download the PDF version of this report (710kb):






   

    AA23-136A_StopRansomware_BianLian_Ransomware_Group.pdf
    (PDF,       644.23 KB
  )

 


For a downloadable copy of IOCs (35kb), see:






   

    AA23-136A.STIX_.xml
    (XML,       34.72 KB
  )

 


For a downloadable copy of IOCs in JSON format, see AA23-136A.stix.json


Technical Details


Note:

Let's not argue. Let's network!