Government and industry reporting described multi-stage intrusions in which ransomware and extortion actors gained access through unpatched Microsoft Exchange ProxyShell flaws, phishing, compromised credentials, and exposed RDP services. Truesec documented attacks where ProxyShell-compromised Exchange servers were used to hijack existing email threads and deliver Datoploader/Squirrelwaffle and QBot, after which a likely Conti-affiliated actor used Cobalt Strike, RDP, and privilege escalation to move laterally, enumerate Active Directory, exfiltrate sensitive data, delete backups, and deploy Conti ransomware. A recurring artifact in the phishing stage was the Exchange MessageClass value IPM.Blabla, and infected hosts created C:\Datop before executing payloads with regsvr32.exe and persistence via registry autoruns or scheduled tasks.

TTPs, infrastructure, and targeting history in one profile.
16 events from the most recent confirmed update back to the earliest known activity.
On November 20, 2024, the FBI, CISA, and ASD's ACSC updated their BianLian advisory with additional tactics, techniques, procedures, and indicators derived from investigations and intelligence through June 2024.
The updated CISA advisory states that BianLian shifted exclusively to exfiltration-only extortion around January 2024, ending its historical double-extortion model.
The FBI, CISA, and the Australian Cyber Security Centre published a joint #StopRansomware advisory detailing BianLian ransomware and extortion activity, including TTPs and IOCs.
Talos reported that the MoneyMessage ransomware operation was first discovered in March 2023 and uses a double-extortion model.
Talos Incident Response reported that in Q2 2023, data-theft extortion rose 25 percent from the prior quarter and became its most-observed threat category, surpassing ransomware.
In a Q2 2023 incident, Talos observed a Clop affiliate exploit the GoAnywhere MFT remote code execution vulnerability CVE-2023-0669, exfiltrate victim data, and extort without deploying ransomware.
During Q2 2023, Talos Incident Response observed 8Base and MoneyMessage ransomware operations for the first time in its engagements.
During Q2 2023, Cisco Talos Incident Response observed RansomHouse and Karakurt data-theft extortion activity for the first time in its engagements.
Talos said a free decrypter for BianLian ransomware was released in January 2023 and may have contributed to the group's move away from encryption.
A joint advisory cited by Talos stated that BianLian had stopped ransomware operations in favor of exfiltration-based extortion as of January 2023.
CISA's advisory states that the FBI has observed BianLian affecting organizations in multiple U.S. critical infrastructure sectors since June 2022.
Starting in early November 2021, attackers used the compromised Exchange servers to send phishing emails that hijacked existing threads and delivered malicious ZIP archives containing macro-enabled Excel files.
Truesec identified multiple Microsoft Exchange servers compromised via the ProxyShell exploit chain in a series of attacks that later led to Conti ransomware deployment.
Talos reported that the RansomHouse extortion operation has been active since late 2021 and is known for exploiting vulnerabilities to access corporate environments.
Talos noted that the Karakurt data-theft extortion group has been active since 2021, typically gaining access through valid accounts, phishing, or vulnerability exploitation.
After victims opened the phishing payloads, Datoploader/Squirrelwaffle and QBot were installed, followed within minutes or hours by Cobalt Strike, privilege escalation, data hunting, backup deletion, and Conti ransomware deployment.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 37 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourceblog.talosintelligence.com
Open sourcetruesec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.