BianLian Ransomware Attack on Nobiskrug in Germany

Year

2023

Month

March

Reference number

20230303

Impact area

Shore

Incident location

Germany

Incident country

Germany

Victim country

Germany

Victim identity

Nobiskrug

Victim Type

Shipbuilding company

Method

Ransomware

Summary:

In March 2023, the Flensburger Schiffbau-Gesellschaft (FSG) and the Rendsburg shipyard Nobiskrug in Germany were targeted by the BianLian ransomware group. The attack led to the sealing off of all IT systems, with the group claiming access to 3TB of company data. The US Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Australian Cyber Security Centre (ACSC) have warned critical infrastructure organizations about BianLian's activities. Active since June 2022, the group uses remote desktop protocol (RDP) credentials, often obtained through phishing, to infiltrate networks. Since January 2023, BianLian has focused on data exfiltration rather than file encryption, using custom Go-based backdoors and various tools for reconnaissance and credential harvesting. They threaten to publish stolen data unless a ransom is paid in cryptocurrency. Organizations are advised to audit RDP usage, disable command-line scripting, and implement strong authentication practices to defend against such attacks.

Reference URL

https://icsstrive.com/incident/cyberattacks-on-north-german-shipyards/
https://www.securityweek.com/critical-infrastructure-organizations-warned-of-bianlian-ransomware-attacks/
https://www.picussecurity.com/resource/blog/bianlian-ransomware-analysis-the-rise-of-exfiltration-based-extortion