BianLian ransomware targets companies by using fake invoice SVG image files that secretly download malware and encrypt data at high speed. A simple image can now compromise an entire network.

Read: https://hackread.com/bianlian-ransomware-fake-invoice-svg-images-attacks/

#CyberSecurity #BianLian #Ransomware #Phishing #Malware

BianLian Ransomware Spreads via Fake Invoice SVG Images in New Attacks

BianLian ransomware targets Venezuelan companies with phishing emails using malicious SVG image files to deploy fast AES ransomware attacks.

Hackread - Cybersecurity News, Data Breaches, AI and More
Khám phá nghệ thuật "Bianlian" - ma thuật thay đổi khuôn mặt ở Thành Đô! Với thời gian và sự bí ẩn, những nghệ sĩ làm cho bạn không thể chớp mắt với những màn biểu diễn sống động. Đừng bỏ lỡ trải nghiệm độc đáo này khi đến Tứ Xuyên! #Bianlian #ThànhĐô #VănHóaTrungQuốc https://ift.tt/N2kxfrj
Chớp Mắt Là Bỏ Lỡ: Ma Thuật Thay Đổi Khuôn Mặt Của Thành Đô - Thế Giới Trong Tầm Tay

Khám phá ma thuật của bianlian – nghệ thuật thay đổi khuôn mặt trong Kinh kịch Tứ Xuyên – được tái hiện sống động tại các quán trà ở Thành Đô. Một màn trình diễn không thể bỏ lỡ.

Thế Giới Trong Tầm Tay - Thế giới của bạn, tin tức của bạn, cách bạn muốn
Shifting the sands of RansomHub’s EDRKillShifter

ESET researchers discover new ties between affiliates of RansomHub and of rival gangs Medusa, BianLian, and Play.

New post from #Bianlian : Meridian Senior
More at : https://www.ransomlook.io/group/Bianlian #Ransomware
bianlian details

New post from #Bianlian : Saunders And Saunders
More at : https://www.ransomlook.io/group/Bianlian #Ransomware
bianlian details

New post from #Bianlian : Cmc Technology Group
More at : https://www.ransomlook.io/group/Bianlian #Ransomware
bianlian details

New post from #Bianlian : Sonrisas Dental Health
More at : https://www.ransomlook.io/group/Bianlian #Ransomware
bianlian details

#ESETresearch discovered previously unknown links between the #RansomHub, #Medusa, #BianLian, and #Play ransomware gangs, and leveraged #EDRKillShifter to learn more about RansomHub’s affiliates. @SCrow357 https://www.welivesecurity.com/en/eset-research/shifting-sands-ransomhub-edrkillshifter/
RansomHub emerged in February 2024 and in just three months reached the top of the ransomware ladder, recruiting affiliates from disrupted #LockBit and #BlackCat. Since then, it dominated the ransomware world, showing similar growth as LockBit once did.
Previously linked to North Korea-aligned group #Andariel, Play strictly denies operating as #RaaS. We found its members utilized RansomHub’s EDR killer EDRKillShifter, multiple times during their intrusions, meaning some members likely became RansomHub affiliates.
BianLian focuses on extortion-only attacks and does not publicly recruit new affiliates. Its access to EDRKillShifter suggests a similar approach as Play – having trusted members, who are not limited to working only with them.
Medusa, same as RansomHub, is a typical RaaS gang, actively recruiting new affiliates. Since it is common knowledge that affiliates of such RaaS groups often work for multiple operators, this connection is to be expected.
Our blogpost also emphasizes the growing threat of EDR killers. We observed an increase in the number of such tools, while the set of abused drivers remains quite small. Gangs such as RansomHub and #Embargo offer their killers as part of the affiliate program.
IoCs available on our GitHub: https://github.com/eset/malware-ioc/tree/master/ransomhub
Shifting the sands of RansomHub’s EDRKillShifter

ESET researchers discover new ties between affiliates of RansomHub and of rival gangs Medusa, BianLian, and Play.

New post from #Bianlian : Goshen Medical Center
More at : https://www.ransomlook.io/group/Bianlian #Ransomware
bianlian details