The BianLian ransomware group has changed its focus, now aiming only at extracting data found on compromised networks and using it for blackmail.
Security experts Redacted recently uncovered the emergence of BianLian's operational evolution, where they observed that this threat group is trying to sharpen its extortion skills and increase the pressure on victims .
BianLian, a notorious ransomware group that emerged in July 2022, has successfully infiltrated many prominent organizations around the world.
In January 2023, Avast introduced a free decryptor that allows victims to regain access to files that had been compromised by ransomware.
See also: Winter Vivern hackers use fake antivirus scanners to distribute malware

Recent BianLian attacks
Reports indicate that the BianLian malware actors remained consistent with their initial access and lateral movement tactics, continuing to insert a custom Go into victims’ devices for remote access. This new version of the malware is slightly improved over previous versions.
Cybercriminals waste no time when it comes to extortion – within two days of the breach, their victims are already posted on their website in disguised form. Victims then have a limited 10-day window to pay the ransom.
By March 13, 2023, the BianLian group had listed 118 victim companies on its extortion portal – the majority of these were American businesses at an impressive 71%!
Unlike previous attacks, BianLian's newest strategy does not involve encrypting the compromised victim 's files . Instead, it only attempts to generate revenue through threatening data exposure.
See also: Russian hackers used Outlook to attack European companies
Using thorough analysis of the laws in their victims’ regions, BianLian’s entrepreneurs master the art of intimidation, leveraging relevant regulations to escalate their demands. Redacted has found that this technique often works effectively, as many threats made by these criminals fall close to legal boundaries.
Whether BianLian chose to abandon the encryption technique because of Avast's successful decryptor or because it realized that ransomware could occur without it remains a mystery.
It should be mentioned that when Avast released its free decryptor, BianLian downplayed its importance, saying that it would only work on versions of the ransomware as of “summer 2022” and would destroy files encrypted by all subsequent versions.

See also: Russia – Ukraine: Microsoft warns of new Sandworm attacks
Blackmail without encryption
Cybercriminals often use a form of “double blackmail” to increase pressure on their victims, which includes file encryption and data theft, as well as threatening statements about leaking stolen information.
However, by evaluating the interactions between criminals and their victims, ransomware gangs eventually realized that in many cases the data breach was an even more compelling incentive for payment.
This progress has resulted in the widespread emergence of non-encryption ransomware operations, such as Babuk and SnapMC, as well as extortion schemes that claim not to be involved with file encryption (or any other), such as RansomHouse, Donut, and Karakurt.
Despite this, most ransomware groups still choose to encrypt victims’ devices in their attacks due to the dramatic impact it has on business operations. This puts enormous pressure on victims and thus increases the likelihood of success of extortion attempts.
Information source: bleepingcomputer.com
