Last seven days
- First activity
- Aug 18, 2026
- Last activity
- Aug 18, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
BianLian is a name used for two distinct malware contexts: a Go-based ransomware and extortion operation targeting enterprise environments, and an unrelated Android banking malware family.
Profile source: Mallory opens in a new tabBianLian
BianLian is a name used for two distinct malware contexts: a Go-based ransomware and extortion operation targeting enterprise environments, and an unrelated Android banking malware family. In enterprise intrusions, BianLian emerged as a ransomware actor using custom Go malware including a backdoor and an encryptor. It has been observed gaining initial access through exploitation of ProxyShell vulnerabilities, attacks on SonicWall VPN appliances, and abuse of weak or exposed remote-access credentials. After access, operators rely heavily on living-off-the-land techniques such as RDP, WinRM, WMI, and PowerShell for reconnaissance, lateral movement, persistence, and defense evasion. Reported behaviors include disabling or bypassing security controls, modifying firewall and remote-access settings, deleting backups and shadow copies, exfiltrating data with common administrative tools, and deploying a custom backdoor that can retrieve and execute payloads in memory. BianLian initially operated as a double-extortion ransomware, but by early 2023 it was widely reported to have shifted toward exfiltration-based extortion without file encryption. Victims have included organizations in manufacturing, healthcare, education, information and communications, and other sectors, with activity concentrated in North America, the United Kingdom, and Australia.
Separately, Android/BianLian is a banking trojan family first publicly discussed in 2018 and primarily associated with campaigns targeting Turkish banking and financial applications, later expanding to additional regions and app categories including cryptocurrency services. This Android malware abuses Accessibility Services, hides its icon, dynamically loads secondary components, and communicates with command-and-control infrastructure over HTTP. Its modular capabilities include SMS interception and sending, overlay-based credential theft, USSD execution, device locking, notification suppression, PIN theft or manipulation, screen capture or screencasting, remote app installation, and TeamViewer-assisted remote access. Some variants also implement SOCKS5 or SSH proxy functionality and retrieve updated command-and-control information from remote intermediary services. Because the same name is used for both the enterprise extortion malware and the Android banking trojan, analysts should distinguish them carefully; available reporting has explicitly noted no observed operational connection between the Android banking malware and the BianLian ransomware group.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
The BianLian group has developed a custom tool set consisting of a backdoor and an encryptor, developing both using the Go programming language.
Exploited software
MITRE ATT&CK
Reporting
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.