The FBI is telling businesses to stop using remote desktop software - here's why

Ransomware attack on a computer
(Image credit: Kaspersky)

The FBI, the US Cybersecurity and Infrastructure Security Agency (CISA), and the Australian Cyber Security Centre (ACSC) are urging businesses to "strictly limit the use of Remote Desktop Protocol (RDP) and other remote desktop services" and thus minimize the threat coming from the BianLian ransomware group.

In a joint security advisory the law enforcement agencies said BianLian usually targets Windows systmes through RDP credentials, before deploying additional software to steal more credentials, or exfiltrate sensitive data and other important files.

Given that RPD is BianLian's usual point of entry, locking the door seems like a logical step forward. 

Reducing the impact

The law enforcement agencies also said businesses should increase PowerShell logging, add time-based locks to accounts, as well as track domain controllers and active directories for suspicious new accounts and other shady activities. 

"FBI, CISA, and ACSC encourage critical infrastructure organizations and small- and medium-sized organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of BianLian and other ransomware incidents," the advisory reads.

We last heard of BianLian in March 2023, when cybersecurity researchers Redacted spotted the group attempting to extort businesses for money - without encrypting their endpoints first. 

Researchers came up with two possible explanations as to why the threat actors ditched the encryptor, one being that the whole ordeal is too time-consuming, too costly, and redundant, and the other one being that the group never recovered from Avast’s decryptor which was released in January this year. In any case, should your business suffer a ransomware encryption, the FBI recommends not paying the ransom demand.

BianLian was first observed in June 2022, targeting businesses in the healthcare industry, as well as other critical infrastructure verticals.

In a report by The Register, it was said that BianLian is actually multiple ransomware groups growing in size and using newer programming languages, such as Go, or Rust. 

Via: The Register

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag
China government-linked hackers caught running a seriously dangerous ransomware scam
Representational image of a cybercriminal
Should ransomware payments be illegal?
data recovery
Ghost ransomware has hit firms in over 70 countries, FBI and CISA warn
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Interlock ransomware attacks highlight need for greater security standards on critical infrastructure
Hacker silhouette working on a laptop with North Korean flag on the background
FBI claims North Korean workers are hacking the US companies which hired them
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand