Headlines

BianLian Ransomware Poses Threat to Critical Infrastructure Organizations

BianLian Ransomware Poses Threat to Critical Infrastructure Organizationsransomware,cybersecurity,criticalinfrastructure,BianLian,threat,organizations
Cybersecurity experts from the US Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI) and the Australian Cyber Security Centre (ACSC) have issued a warning to critical infrastructure organizations about the threats posed by the BianLian ransomware group. This malicious group has been active since at least June 2022, with a recent focus on data exfiltration.

According to the experts, the BianLian group gains access to victim networks via remote desktop protocol (RDP) credentials, which were likely obtained through phishing attacks or brokers. After gaining access to the network, the group deploys a custom Go-based backdoor, specific to each victim, and installs software such as Atera Agent, AnyDesk, SplashTop, and TeamViewer to gain remote management and access.

The group targets multiple critical infrastructure organizations in the US and private entities in Australia, including a critical infrastructure organization, by exploiting vulnerabilities such as the Netlogon vulnerability (CVE-2020-1472) and using reconnaissance tools like SoftPerfect Network Scanner, SharpShares, PingCastle, and Impacket. Once victim data is harvested, it is exfiltrated via FTP or Mega file-sharing services. In cases where ransomware was deployed and executed, the encrypted files had .bianlian extension. In such cases, the group also threatened to publish the exfiltrated data on leak sites, forcing the victims to pay the ransom in cryptocurrency if they wanted the data to remain confidential.

To mitigate the threat posed by the BianLian group and similar ransomware attacks, CISA, FBI, and ACSC recommend organizations to keep all systems and software updated, implement strong authentication practices, maintain offline backups and devise a recovery plan. They also encourage companies to audit the use of RDP and other remote access tools, disable command-line scripting, restrict PowerShell usage, control software execution, and audit user accounts.

The rise in ransomware attacks in recent years has made internet security an urgent priority for businesses and individuals alike. By adopting a proactive approach and implementing effective security measures, companies can reduce the risks of cyber-attacks that can disrupt operations and potentially compromise sensitive information. In case of a cyber breach, having an updated recovery plan is crucial to ensure incident response and minimize damage.

Cybersecurityransomware,cybersecurity,criticalinfrastructure,BianLian,threat,organizations


BianLian Ransomware Poses Threat to Critical Infrastructure Organizations
<< photo by Jorge Jesus >>

You might want to read !