A joint cybersecurity advisory, published by the Cybersecurity and Infrastructure Security Agency (CISA), has been issued by US and Australian government agencies, warning organizations about the latest tactics, techniques, and procedures (TTPs) used by the BianLian ransomware group.
BianLian is a ransomware and data extortion group that has been targeting entities in critical infrastructure in the US and Australia since June 2022.
As part of the #StopRansomware effort, this advisory is based on research by the Federal Bureau of Investigation (FBI) and the Australian Cyber Security Centre (ACSC), from March 2023. It aims to provide defenders with information that will allow them to adjust their protections and strengthen their security posture against BianLian ransomware and other similar threats.
See also: Ransomware group asks for charity donation instead of ransom

See also: Malicious Microsoft VSCode extensions steal passwords
Bianlian attack tactics
BianLian initially used a double extortion model, encrypting systems after stealing private data from victims' networks and then threatening to publish the files.
However, since January 2023, when Avast released a decryptor for the ransomware, the group has switched to extortion based on data theft without encrypting their systems .
This tactic is still imperative, as the incidents essentially involve data breaches that cause damage to the victim's reputation, undermine customer trust, and introduce legal complications.
The CISA advisory warns that BianLian compromises systems using valid Remote Desktop Protocol (RDP) credentials, which may have been purchased from initial access brokers or obtained through phishing.
BianLian then uses a custom backdoor written in Go, commercial remote access tools, and command-line scripts for network reconnaissance. The final stage consists of isolating the victim's data via File Transfer Protocol (FTP), the Rclone tool, or the Mega file hosting service.
To evade detection by security software, BianLian uses PowerShell and Windows Command Shell to disable running processes associated with antivirus tools. The Windows registry is also manipulated to neutralize the tamper protection provided by Sophos security products.
See also: Cisco: Warns of critical switch flaws with public exploit code

Suggested mitigations
Recommended mitigations include limiting the use of RDP and other remote desktop services, disabling command line and scripting-related activities , and limiting the use of PowerShell on critical systems
The advisory recommends several measures that can help defend the network.
- Check the execution of remote access tools and software on your network.
- Limit the use of remote desktop services like RDP and enforce strict security measures.
- Limit your use of PowerShell, update to the latest version, and enable enhanced logging.
- Regularly audit administrative accounts and apply the principle of least privilege.
- Develop a recovery plan with multiple copies of data stored securely and offline.
- Comply with NIST standards for password management, including length, storage, reuse, and multi-factor authentication.
- Regularly update software and firmware, segment networks for improved security, and actively monitor network activity.
More detailed information on recommended mitigations, indicators of compromise (IoCs), command traces, and BianLian techniques are available in the full CISA and ACSC bulletins.
Information source: bleepingcomputer.com
