The BianLian ransomware group has shifted its tactics and now focuses solely on data exfiltration instead of encrypting victim devices, according to an updated advisory by CISA.
The group steals sensitive data and threatens to leak it if payment is not made.
This change aligns with the trend of ransomware groups moving away from encryption due to the complexity and cost involved.
BianLian is a Russian actor with Russian affiliates, intentionally using foreign-language names to complicate attribution efforts.