BianLian Ransomware Attack on Bolidt

Year

2023

Month

January

Reference number

20230110

Impact area

Shore

Incident location

Netherlands

Incident country

Netherlands

Victim country

Netherlands

Victim identity

Bolidt

Victim Type

Company office

Method

Ransomware

Summary:

In January 2023, the BianLian ransomware group shifted its focus from file encryption to data theft-based extortion, following the release of a decryption tool by Avast. Active since June 2022, the group gains access to networks via Remote Desktop Protocol (RDP) credentials, often acquired through phishing or initial access brokers. They use custom Go-based backdoors, remote management software, and various tools for reconnaissance and credential harvesting. The group threatens to publish exfiltrated data on a leak site and demands ransom payments in cryptocurrency. To evade detection, BianLian disables antivirus processes using PowerShell and Windows Command Shell. The US Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Australian Cyber Security Centre (ACSC) have issued warnings to critical infrastructure organizations. Recommended mitigations include auditing RDP usage, disabling command-line scripting, restricting PowerShell, and maintaining strong authentication practices.

Reference URL

https://www.securityweek.com/critical-infrastructure-organizations-warned-of-bianlian-ransomware-attacks/
https://www.csoonline.com/article/574801/bianlian-ransomware-group-shifts-focus-to-extortion.html
https://www.bleepingcomputer.com/news/security/fbi-confirms-bianlian-ransomware-switch-to-extortion-only-attacks/