Skip to content

BianLian

BianLian is a Russia-linked ransomware and data-extortion operation first observed in 2022 that has targeted organizations in the United States, Australia, and other countries, including critical infrastructure and sectors such as healthcare, manufacturing, media and entertainment, professional services, property development, and mining.

Profile source: Mallory opens in a new tab

BianLian

Family profile

BianLian is a Russia-linked ransomware and data-extortion operation first observed in 2022 that has targeted organizations in the United States, Australia, and other countries, including critical infrastructure and sectors such as healthcare, manufacturing, media and entertainment, professional services, property development, and mining. The group historically conducted double-extortion intrusions involving data theft and file encryption, but after a public decryptor became available in early 2023 it shifted largely to exfiltration-led extortion and by 2024 was widely reported as operating primarily or exclusively without deploying an encryptor in many cases.

BianLian has used multiple initial access routes, including valid Remote Desktop Protocol credentials, phishing, and exploitation of public-facing applications. Public reporting and government advisories also associate the group with exploitation of Microsoft Exchange ProxyShell vulnerabilities and with abuse of JetBrains TeamCity CVE-2024-27198 in extortion operations. Once inside a network, BianLian has deployed a custom Go-based backdoor tailored to individual victims, installed remote management tooling, created or modified administrator accounts, and used proxy and tunneling utilities to maintain command and control. Observed post-compromise activity includes network and Active Directory discovery, credential theft from LSASS, attempts to access NTDS.dit, lateral movement via PsExec, RDP, and SMB, and defense evasion through PowerShell and command-shell activity that disables security controls. The group has also been observed using webshells for persistence and exploiting Windows privilege-escalation vulnerabilities.

The ransomware component associated with earlier BianLian activity is a Go-based 64-bit Windows executable that encrypts selected files using AES-256-CBC, appends a dedicated extension to encrypted files, drops ransom notes, and self-deletes after execution. Known variants searched across mounted drives and encrypted files matching a large hardcoded extension list. Later operations increasingly emphasized theft of sensitive data and coercive leak threats rather than disruptive encryption.

BianLian is commonly described as a cybercriminal group with Russia-based affiliates and has been repeatedly tracked in joint government advisories and industry reporting as a significant ransomware and extortion threat. The operation has also been linked to abuse-resistant hosting ecosystems that supported its infrastructure. Victim reporting and broader ransomware trend analyses consistently place BianLian among notable extortion actors affecting sensitive sectors, especially organizations where stolen data can create regulatory, operational, or geopolitical pressure.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

Operational record

199
Indicators
1
YARA rules
1
Ransom notes
3
Leak sites
0 available

Credential Theft

  • RDP Recognizer

Discovery Enum

  • Advanced IP Scanner
  • Advanced Port Scanner
  • PingCastle
  • SharpShares
  • SoftPerfect NetScan
  • WKTools

Exfiltration

  • MEGA
  • RClone

LOLBAS

  • PsExec

Offsec

  • Impacket

RMM Tools

  • AmmyyAdmin
  • AnyDesk
  • Atera
  • ScreenConnect
  • Splashtop
  • TeamViewer

Published indicators

Md5

8 total
  • 36171704cde087f839b10c2465d864e1
  • d10e0387e3d55dc1f82c23719e2b168b
  • 0c756fc8f34e409650cd910b5e2a3f00
  • b3cdf0489ff37fe65141be9363b9489c
  • 08e76dd242e64bb31aec09db8464b28f
  • 14da9c0c4e3ac3b9abb2c48b37bece19
  • 15cdfa777aa2db35229410d2fa9fb92e
  • 7be61ea851f894d26bf57cf0f1f55ed6

Ip

191 total
  • 88.212.241.105:993
  • 91.245.255.27:8443
  • 162.33.179.99:1433
  • 151.236.16.144:64250
  • 172.96.137.108:80
  • 31.220.80.82:8081
  • 104.238.35.179:38901
  • 151.236.16.242:12818
  • 104.238.35.179:3389
  • 85.235.151.5:8080

Reported operators

Threat actors

1 named in public reporting
BianLian

...BianLian Ransomware Gang... leveraged command and scripting tools

Exploited software

Vulnerabilities linked to BianLian

4 CVEs

MITRE ATT&CK

BianLian in ATT&CK

21 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.