Skip to content

BianLian

BianLian is a name used for two distinct malware contexts: a Go-based ransomware and extortion operation targeting enterprise environments, and an unrelated Android banking malware family.

Profile source: Mallory opens in a new tab

BianLian

Family profile

BianLian is a name used for two distinct malware contexts: a Go-based ransomware and extortion operation targeting enterprise environments, and an unrelated Android banking malware family. In enterprise intrusions, BianLian emerged as a ransomware actor using custom Go malware including a backdoor and an encryptor. It has been observed gaining initial access through exploitation of ProxyShell vulnerabilities, attacks on SonicWall VPN appliances, and abuse of weak or exposed remote-access credentials. After access, operators rely heavily on living-off-the-land techniques such as RDP, WinRM, WMI, and PowerShell for reconnaissance, lateral movement, persistence, and defense evasion. Reported behaviors include disabling or bypassing security controls, modifying firewall and remote-access settings, deleting backups and shadow copies, exfiltrating data with common administrative tools, and deploying a custom backdoor that can retrieve and execute payloads in memory. BianLian initially operated as a double-extortion ransomware, but by early 2023 it was widely reported to have shifted toward exfiltration-based extortion without file encryption. Victims have included organizations in manufacturing, healthcare, education, information and communications, and other sectors, with activity concentrated in North America, the United Kingdom, and Australia.

Separately, Android/BianLian is a banking trojan family first publicly discussed in 2018 and primarily associated with campaigns targeting Turkish banking and financial applications, later expanding to additional regions and app categories including cryptocurrency services. This Android malware abuses Accessibility Services, hides its icon, dynamically loads secondary components, and communicates with command-and-control infrastructure over HTTP. Its modular capabilities include SMS interception and sending, overlay-based credential theft, USSD execution, device locking, notification suppression, PIN theft or manipulation, screen capture or screencasting, remote app installation, and TeamViewer-assisted remote access. Some variants also implement SOCKS5 or SSH proxy functionality and retrieve updated command-and-control information from remote intermediary services. Because the same name is used for both the enterprise extortion malware and the Android banking trojan, analysts should distinguish them carefully; available reporting has explicitly noted no observed operational connection between the Android banking malware and the BianLian ransomware group.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 18, 2026
Last activity
Aug 18, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • PK1

Leading providers

  • LIGHT NODE LIMITED1

Infrastructure traits

  • Hosting 1

Reported operators

Threat actors

1 named in public reporting
BianLian

The BianLian group has developed a custom tool set consisting of a backdoor and an encryptor, developing both using the Go programming language.

Exploited software

Vulnerabilities linked to BianLian

7 CVEs

MITRE ATT&CK

BianLian in ATT&CK

55 distinct techniques

Techniques

55 techniques
T1071 Application Layer Protocol T1486 Data Encrypted for Impact T1657 Financial Theft T1027 Obfuscated Files or Information T1620 Reflective Code Loading T1059 Command and Scripting Interpreter T1056 Input Capture T1113 Screen Capture T1105 Ingress Tool Transfer T1041 Exfiltration Over C2 Channel T1090 Proxy T1564 Hide Artifacts T1546.008 Accessibility Features T1129 Shared Modules T1574.006 Dynamic Linker Hijacking T1140 Deobfuscate/Decode Files or Information T1027.002 Software Packing T1548 Abuse Elevation Control Mechanism T1036 Masquerading T1497 Virtualization/Sandbox Evasion T1021.005 VNC T1071.001 Web Protocols T1091 Replication Through Removable Media T1021.006 Windows Remote Management T1547 Boot or Logon Autostart Execution T1562 Impair Defenses T1082 System Information Discovery T1056.002 GUI Input Capture T1018 Remote System Discovery T1078 Valid Accounts T1098 Account Manipulation T1562.001 Disable or Modify Tools T1047 Windows Management Instrumentation T1069 Permission Groups Discovery T1083 File and Directory Discovery T1112 Modify Registry T1568 Dynamic Resolution T1070 Indicator Removal T1218 System Binary Proxy Execution T1059.001 PowerShell T1546 Event Triggered Execution T1219 Remote Access Tools T1190 Exploit Public-Facing Application T1090.003 Multi-hop Proxy T1204 User Execution T1562.004 Disable or Modify System Firewall T1021.001 Remote Desktop Protocol T1120 Peripheral Device Discovery T1518 Software Discovery T1497.001 System Checks T1056.001 Keylogging T1539 Steal Web Session Cookie T1056.003 Web Portal Capture T1213 Data from Information Repositories T1567 Exfiltration Over Web Service

Reporting

Research mentioning BianLian

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

Aug 12
Hookphish

Ransomware Group clop Hits: LARGAN.COM.TW

Apr 19
Bleeping Computer

March 2023 broke ransomware attack records with 459 incidents

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.