heise online · @heiseonline
50119 followers · 6303 posts · Server social.heise.de
dispatch · @dispatch
541 followers · 3119 posts · Server ioc.exchange
ITSEC News · @itsecbot
1293 followers · 35205 posts · Server schleuss.online

Take action now to avoid BianLian ransomware attacks, US Government warns organisations - A joint alert has been issued by US government agencies, advising organisations of the st... tripwire.com/state-of-security

#malware #bianlian #dataloss #lawℴ #guestblog #databreach #ransomware

Last updated 1 year ago

Salvatore Lombardo · @Slvlombardo
5 followers · 125 posts · Server mstdn.social
Geekmaster 👽:system76: · @Geekmaster
166 followers · 1245 posts · Server ioc.exchange
Dissent Doe :cupofcoffee: · @PogoWasRight
1303 followers · 141 posts · Server infosec.exchange
Dissent Doe :cupofcoffee: · @PogoWasRight
1288 followers · 102 posts · Server infosec.exchange

BianLian's account on BreachForums lists a law firm they claim to have attacked and snagged 423 GB of data from.

Of course, they don't name them at this point, but their victim appears to be Adami, Shuffield, Scheihing & Burns in San Antonio, TX.

#databreach #ransomware #dataprotection #infosec #cybersecurity #bianlian

Last updated 1 year ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1262 followers · 117 posts · Server infosec.exchange

BianLian doesn't seem to get a lot of media coverage, but they've hit a number of entities in the healthcare sector already, including one hospital.

BianLian recently posted samples from some unnamed victims on Breached -- but it was easy to determine the victims from the samples: Northeast Surgical Group, Zerbe Retirement Community, and Arizona Reproductive Medicine Specialists. None of the three have any notice on their websites at this time.

Today, BianLian dumped data from Northeast Surgical Group on their leak site. They also dumped data from Suburban Laboratories in Illinois.

There is nothing on Suburban's website about any incident, and none of these victims have yet to appear on HHS's public breach tool.

Perhaps HHS should provide a threat brief or analyst note on BianLian, including the availability of any free decryptor.

#bianlian #databreach #ransomware #infosec #healthsec #cybersecurity

Last updated 1 year ago

More data leaked from St. Rose Hospital ransomware incident: databreaches.net/more-data-lea

It turns out the hospital, which has steadfastly ignored all inquiries from my site, allegedly did negotiate with the threat actors and then refused to pay ransom.

And it seems like they haven't informed patients and employees that their or has been leaked on the dark web and clear net.

The incident hasn't shown up on 's breach tool yet so we don't have total number affected yet.

#pii #phi #hhs #ransomware #databreach #infosec #cybersecurity #dataprotection #bianlian #transparency

Last updated 2 years ago

Well done for releasing a free for the strain to help victims of the malware recover locked files without paying the hackers 👏

bleepingcomputer.com/news/secu

#avast #decryptor #bianlian #ransomware #cybersecurity #infosec #malware

Last updated 2 years ago

Redhotcyber · @redhotcyber
351 followers · 373 posts · Server mastodon.bida.im

Avast rilascia il decryptor per BianLian ransomware

La società di di sicurezza ha rilasciato un gratuito per il . Il decryptor aiuta le vittime del a recuperare i file bloccati senza trasferire denaro agli aggressori.

Il decryptor è circa sei mesi dopo l’aumento dell’attività del BianLian. Nell’estate del 2022 il è stato utilizzato in modo massiccio, infatti, diverse organizzazioni ben note sono state violate.

lnkd.in/d_k4CrMJ

#infosecurity #privacy #CyberSecurityNews #cybersecuritytraining #CyberSecurityAwareness #cybercrime #cybersecurity #hacking #dataprotection #ethicalhacking #informationsecurity #redhotcyber #apparso #bianlian #ransomware #decryptor #avast #software

Last updated 2 years ago

securityaffairs · @securityaffairs
336 followers · 217 posts · Server infosec.exchange
Dominic Alvieri · @AlvieriD
42 followers · 62 posts · Server infosec.exchange

St. Rose Hospital in Hayward, California posted by BianLian.

#cybersecurity #infosec #bianlian

Last updated 2 years ago

CyberCrymen · @cybercrymen
15 followers · 22 posts · Server infosec.exchange
CyberCrymen · @cybercrymen
15 followers · 22 posts · Server infosec.exchange

The big names of hacker groups.

Check out the list of the most notorious hack groups of 2020.

cybernews.com/editorial/most…

#hackers #hackgroup #apt #bianlian #hive #lockbit #BlackBasta #ALPHV #blackcat

Last updated 2 years ago

CyberCrymen · @cybercrymen
5 followers · 7 posts · Server infosec.exchange
Geekmaster 👽 · @Geekmaster
68 followers · 397 posts · Server ioc.exchange

I have been seeing A LOT of verified compromises circulating hacker forums because of , , , , , , , , - I'm talking multiple terabytes of data, hundreds of millions of account details, across pretty much every single sector. Most common method of infection? ! Be super mindful of the links you click on, the attachments you download, and the sites you visit

#blackcat #lockbit #hiveransomware #Mallox #blackbasta #royalransomware #bianlian #cubaransomware #bloodyransomwaregang #RANSOMEXX #Businessemailcompromise

Last updated 2 years ago

Taggart: ~# :idle: · @mttaggart
2488 followers · 2322 posts · Server fosstodon.org

Some of this week's work product. Turns out the ransomware group uses a non-stripped version of the SHARPDEKE cryptor, so detection isn't so tricky. otx.alienvault.com/pulse/6388e

#bianlian #blueteam #threatintel #infosec #cybersecurity

Last updated 2 years ago

Taggart: ~# :idle: · @mttaggart
2439 followers · 2232 posts · Server fosstodon.org

I'm doing some research into the ransomware group, and I'd just like to thank the authors of the cryptor for not stripping the Go debug symbols. 🙏

#bianlian #sharpdeke #malware #infosec #cybersecurity

Last updated 2 years ago

TropChaud · @IntelScott
152 followers · 23 posts · Server infosec.exchange

Good article highlighting ongoing threats involving U.S. entities over a holiday, when security teams are likely especially under-staffed or at least less focused: therecord.media/cincinnati-sta

In total, ransomware operators publicly threatened five schools and colleges on extortion sites over the past week, the latest in a rising number of such threats involving higher & lower education over the past year. On top of the cases mentioned in the article, the & ransomware groups each also threatened public K-12 school systems in the last week.

The news comes 10 days after the latest U.S. federal government alert focused specifically on Hive, which has threatened a wide range of entities, including orgs. The alert offered a great summary of the techniques & procedures associated with Hive. Here is a fantastic new blog highlighting detection engineering ideas around recent Hive behaviors: micahbabinski.medium.com/catch

A fair amount of intelligence now exists around the other ransomware threatening education orgs last week and over the past year. I look forward to maintaining & expanding this dashboard which shows a combined visual currently covering the nine ransomware threatening schools since last year: app.tidalcyber.com/share/8d9f2

Direct links to specific ransomware heatmaps:

app.tidalcyber.com/share/5f23e
Hive app.tidalcyber.com/share/7d996
BianLian app.tidalcyber.com/share/b5e2d
And some quick metrics and resources around the trend of ransomware extortion threats involving education orgs infosec.exchange/@IntelScott/1

#ransomware #education #hive #bianlian #stopransomware #criticalinfrastructure #healthcare #ttp #vicesociety

Last updated 2 years ago