WatchGuard researchers identified a phishing campaign attributed to the BianLian ransomware group that heavily targets companies in Venezuela with emails in Spanish posing as routine business correspondence. The messages carry malicious .svg attachments disguised as invoices or other business documents; when opened, the files trigger outbound connections to attacker-controlled infrastructure and ultimately download a Go-based Windows payload. The operation uses ja.cat shortened links and compromised Brazilian domains to redirect victims to the final malware, helping the campaign blend in and evade detection.
Researchers said the payload shows clear ransomware behavior, including rapid file encryption with AES, and includes multiple anti-analysis checks such as detecting Wine, monitoring system suspension events, and inspecting settings like GODEBUG. The findings highlight how seemingly benign SVG image files can be weaponized for initial access, and WatchGuard urged defenders to monitor or block the suspicious domains tied to the campaign and scrutinize invoice-themed attachments delivered by email.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
WatchGuard published research describing the SVG-based phishing campaign, its ransomware behavior including rapid AES file encryption, and suspicious domains defenders should block or monitor. The disclosure warned that seemingly harmless SVG files can be weaponized in real-world attacks.
The campaign's SVG attachments triggered connections to external URLs, using ja.cat shortened links and compromised Brazilian domains to redirect victims to a final Go-based Windows payload. Researchers also observed anti-analysis checks including Wine detection, suspension monitoring, and inspection of settings such as GODEBUG.
WatchGuard researchers identified a phishing campaign heavily targeting companies in Venezuela and attributed it to the BianLian ransomware group based on the observed tactics. The emails used malicious SVG attachments disguised as routine Spanish-language business documents such as invoices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.