BianLian attacks Neutronic Stamping

Incident Date: May 30, 2023

Attack Overview
VICTIM
Neutronic Stamping
INDUSTRY
Manufacturing
LOCATION
USA
ATTACKER
Bianlian
FIRST REPORTED
May 30, 2023

Neutronic Stamping and Plating Hit by Ransomware Attack

Neutronic Stamping and Plating, an US-based electronics manufacturer, has been hit with a ransomware attack. BianLian ransomware group has taken responsibility for the incident, posting Neutronic Stamping to its dark web blog page. The group claims to have stolen 480GB of company information including: HR data, Accounting data, Production data, Financial data, SQL databases, and Post archives.

BianLian uploaded Neutronic Stamping to its dark web blog page on May 30, but Neutronic Stamping is yet to confirm the attack. Founded in 1975, Neutronic Stamping and Plating manufactures high-quality electric contacts, pins and lead-frames. It has two sites, both in Fountain Valley, California. It serves the Automotive, Consumer Electronics, Telecom, Defense, and Medical Industries, both in North America and globally.

About BianLian Ransomware Gang

BianLian ransomware gang, which first appeared in June 2022, is a ransomware developer, deployer, and data extortion cybercriminal group. It primarily targets US critical infrastructure but has also attacked professional services, property development, and Australian critical infrastructure sectors.

The ransomware group leverages Remote Desktop Protocol (RDP) credentials to gain access to victims’ systems, using open-source tools and command-line scripting for discovery and credential harvesting, and finally exfiltrating victim data via File Transfer Protocol (FTP), Rclone, or Mega. BianLian then hold organizations to ransom, threating to release the stolen data if the victim fails to pay up.

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.