Skip to content

BianLian

BianLian is a Russia-linked ransomware and data-extortion operation first observed in 2022 that has targeted organizations in the United States, Australia, and other countries, including critical infrastructure and sectors such as healthcare, manufacturing, media and entertainment, professional services, property development, and mining.

Profile source: Mallory opens in a new tab

BianLian

Family profile

BianLian is a Russia-linked ransomware and data-extortion operation first observed in 2022 that has targeted organizations in the United States, Australia, and other countries, including critical infrastructure and sectors such as healthcare, manufacturing, media and entertainment, professional services, property development, and mining. The group historically conducted double-extortion intrusions involving data theft and file encryption, but after a public decryptor became available in early 2023 it shifted largely to exfiltration-led extortion and by 2024 was widely reported as operating primarily or exclusively without deploying an encryptor in many cases.

BianLian has used multiple initial access routes, including valid Remote Desktop Protocol credentials, phishing, and exploitation of public-facing applications. Public reporting and government advisories also associate the group with exploitation of Microsoft Exchange ProxyShell vulnerabilities and with abuse of JetBrains TeamCity CVE-2024-27198 in extortion operations. Once inside a network, BianLian has deployed a custom Go-based backdoor tailored to individual victims, installed remote management tooling, created or modified administrator accounts, and used proxy and tunneling utilities to maintain command and control. Observed post-compromise activity includes network and Active Directory discovery, credential theft from LSASS, attempts to access NTDS.dit, lateral movement via PsExec, RDP, and SMB, and defense evasion through PowerShell and command-shell activity that disables security controls. The group has also been observed using webshells for persistence and exploiting Windows privilege-escalation vulnerabilities.

The ransomware component associated with earlier BianLian activity is a Go-based 64-bit Windows executable that encrypts selected files using AES-256-CBC, appends a dedicated extension to encrypted files, drops ransom notes, and self-deletes after execution. Known variants searched across mounted drives and encrypted files matching a large hardcoded extension list. Later operations increasingly emphasized theft of sensitive data and coercive leak threats rather than disruptive encryption.

BianLian is commonly described as a cybercriminal group with Russia-based affiliates and has been repeatedly tracked in joint government advisories and industry reporting as a significant ransomware and extortion threat. The operation has also been linked to abuse-resistant hosting ecosystems that supported its infrastructure. Victim reporting and broader ransomware trend analyses consistently place BianLian among notable extortion actors affecting sensitive sectors, especially organizations where stolen data can create regulatory, operational, or geopolitical pressure.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 6, 2026
Last activity
Aug 6, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • CN1

Leading providers

  • Shenzhen Tencent Computer Systems Company Limited1

Infrastructure traits

  • Hosting 1

Reported operators

Threat actors

1 named in public reporting
BianLian

...BianLian Ransomware Gang... leveraged command and scripting tools

Exploited software

Vulnerabilities linked to BianLian

4 CVEs

MITRE ATT&CK

BianLian in ATT&CK

12 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.