Year2023 |
MonthMarch |
Reference number20230303 |
Impact areaShore |
Incident locationGermany |
Incident countryGermany |
Victim countryGermany |
Victim identityNobiskrug |
Victim TypeShipbuilding company |
MethodRansomware |
In March 2023, the Flensburger Schiffbau-Gesellschaft (FSG) and the Rendsburg shipyard Nobiskrug in Germany were targeted by the BianLian ransomware group. The attack led to the sealing off of all IT systems, with the group claiming access to 3TB of company data. The US Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Australian Cyber Security Centre (ACSC) have warned critical infrastructure organizations about BianLian's activities. Active since June 2022, the group uses remote desktop protocol (RDP) credentials, often obtained through phishing, to infiltrate networks. Since January 2023, BianLian has focused on data exfiltration rather than file encryption, using custom Go-based backdoors and various tools for reconnaissance and credential harvesting. They threaten to publish stolen data unless a ransom is paid in cryptocurrency. Organizations are advised to audit RDP usage, disable command-line scripting, and implement strong authentication practices to defend against such attacks.