Skip to main content
DFIRLab
ResearchUse CasesCompare
Intel BriefingsThreat Actors
IOC CheckFile AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
Log → SplunkLog → Sentinel
WikiAbout
PlatformNew
DFIRLab

Security research, threat intelligence, and free DFIR tools.

Tools

Phishing CheckerExposure ScannerDomain LookupFile AnalyzerPrivacy CheckLog → SplunkLog → SentinelAPI Playground

Use Cases

SOC Phishing TriageIR IOC EnrichmentMSSP Exposure Monitoringn8n AutomationSee all use cases →

Compare

vs VirusTotalvs Shodanvs TheHiveSee all 8 →

Resources

DFIR WikiIntel BriefingsAboutPlatformAPI Docs

Legal

Privacy PolicyRSS FeedSitemap

© 2026 DFIR Lab. All rights reserved.

All Threat Actors

BianLian

Also known as: BianLian Group, BianLian Ransomware Group, Bitter Scorpius

ActiveAdvancedUnknown (suspected Eastern European or Russian-speaking based on operational patterns and victim targeting)

Profile generated with AI assistance — review before citing.

0Campaigns
66Techniques
99IOCs
42Tools
0Matches
0Infrastructure
OverviewTechniquesToolsIOCsReferences

Overview

BianLian is a Russia-based ransomware developer, deployer, and data extortion cybercriminal group with multiple Russia-based affiliates. Active since June 2022, the group shifted primarily to exfiltration-based extortion in early 2023 after decryption capabilities for their ransomware were released, though they have not completely abandoned encryption. They target critical infrastructure sectors including healthcare, manufacturing, professional services, and legal organizations using compromised RDP credentials, ProxyShell exploits (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and custom Go-based backdoors. The group employs pressure tactics including printing ransom notes to network printers and making threatening phone calls to victims. BianLian typically maintains persistence for extended periods before exfiltration, uses legitimate tools like TeamViewer and AnyDesk for remote access, and leverages various open-source tools for credential harvesting and lateral movement.

Motivations

Financial gainData extortionCybercrime

Target Sectors

Healthcare and Public HealthManufacturingProfessional ServicesLegal ServicesEducationCritical ManufacturingFinancial ServicesInformation TechnologyConstructionEnergyTransportationMediaTechnologyProperty DevelopmentHealthcareLegalRetailTelecommunicationsHospitalityReal EstateMedia and Entertainment

Activity Timeline

First Seen

Jun 2022

Last Seen

Jan 2024

Quick Facts

OriginUnknown (suspected Eastern European or Russian-speaking based on operational patterns and victim targeting)
Sophisticationadvanced
StatusActive

MITRE ATT&CK Techniques

(66)

Initial Access

T1190

Exploit Public-Facing Application

Exploit vulnerabilities in internet-facing applications to gain access.

T1133

External Remote Services

Abuse remote services like VPNs or RDP to gain access to the network.

T1078

Valid Accounts

Use legitimate credentials to authenticate and gain access.

T1566

Phishing

Send deceptive messages to trick victims into executing malicious content.

Other

T1078.003

T1078.003

T1021.004

T1021.004

T1053.005

T1053.005

T1543.003

T1543.003

T1136.001

T1136.001

T1136.002

T1136.002

T1070.004

T1070.004

T1070.001

T1070.001

T1027.002

T1027.002

T1112

T1112

T1562.001

T1562.001

T1003.003

T1003.003

T1555.003

T1555.003

T1087.001

T1087.001

T1087.002

T1087.002

T1482

T1482

T1049

T1049

T1069.001

T1069.001

T1069.002

T1069.002

T1057

T1057

T1033

T1033

T1048.003

T1048.003

T1567.002

T1567.002

T1588.002

T1588.002

T1590

T1590

T1505.003

T1505.003

T1505.004

T1505.004

T1571

T1571

T1530

T1530

T1505.005

T1505.005

T1552.001

T1552.001

T1201

T1201

T1020

T1020

T1036.004

T1036.004

T1098

T1098

T1136.003

T1136.003

T1003.002

T1003.002

T1552.004

T1552.004

T1587.001

T1587.001

T1012

T1012

T1115

T1115

T1537

T1537

T1090.002

T1090.002

Lateral Movement

T1021.001

Remote Desktop Protocol

Use RDP to connect to and control remote systems.

T1021.002

SMB/Windows Admin Shares

Use SMB and administrative shares (C$, ADMIN$) to access remote systems.

Execution

T1047

Windows Management Instrumentation

Use WMI to execute commands and manage systems remotely.

T1059.001

PowerShell

Use PowerShell commands and scripts for execution and automation.

T1059.003

Windows Command Shell

Use cmd.exe to execute commands and batch scripts.

Defense Evasion

T1027

Obfuscated Files or Information

Encrypt, encode, or obfuscate payloads and data to evade detection.

T1036

Masquerading

Disguise malicious artifacts by manipulating names or locations to appear legitimate.

Credential Access

T1003.001

LSASS Memory

Access LSASS process memory to extract credential material.

Discovery

T1083

File and Directory Discovery

Enumerate files and directories to find sensitive data or binaries.

T1018

Remote System Discovery

Discover remote systems on the network for lateral movement targets.

Exfiltration

T1041

Exfiltration Over C2 Channel

Exfiltrate stolen data over the existing command and control channel.

Impact

T1486

Data Encrypted for Impact

Encrypt victim data to disrupt availability, typically for ransom.

T1489

Service Stop

Stop critical services to disrupt operations or aid in data destruction.

Command and Control

T1219

Remote Access Software

Use legitimate remote access tools like TeamViewer or AnyDesk for C2.

T1090

Proxy

Route C2 traffic through intermediary proxies to obscure the source.

Reconnaissance

T1592

Gather Victim Host Information

Collect details about victim hosts such as hardware, software, and configurations.

Collection

T1114

Email Collection

Collect email messages from mailboxes or mail servers.

T1560

Archive Collected Data

Compress or encrypt collected data into archives before exfiltration.

Privilege Escalation

T1068

Exploitation for Privilege Escalation

Exploit software vulnerabilities to gain elevated privileges on a system.

Tools & Malware

(42)

BianLian Ransomware (legacy)

malwareMalicious

Malware used by BianLian.

BianLian Backdoor

malwareMalicious

Malware used by BianLian.

Esxi-args

malwareMalicious

Malware used by BianLian.

PowerShell

legitimate toolLegitimate

Legitimate tool used by BianLian.

Cobalt Strike

frameworkLegitimate

Legitimate tool used by BianLian.

Rclone

legitimate toolLegitimate

Legitimate tool used by BianLian.

Mimikatz

legitimate toolLegitimate

Legitimate tool used by BianLian.

WinRAR

legitimate toolLegitimate

Legitimate tool used by BianLian.

7-Zip

legitimate toolLegitimate

Legitimate tool used by BianLian.

PsExec

legitimate toolLegitimate

Legitimate tool used by BianLian.

AnyDesk

legitimate toolLegitimate

Legitimate tool used by BianLian.

TeamViewer

legitimate toolLegitimate

Legitimate tool used by BianLian.

WinSCP

malwareMalicious

Malware used by BianLian.

FileZilla

malwareMalicious

Malware used by BianLian.

Ngrok

malwareMalicious

Malware used by BianLian.

Windows Remote Desktop Protocol (RDP)

malwareMalicious

Malware used by BianLian.

Windows Management Instrumentation (WMI)

malwareMalicious

Malware used by BianLian.

LaZagne

legitimate toolLegitimate

Legitimate tool used by BianLian.

SharpChrome

malwareMalicious

Malware used by BianLian.

AdFind

legitimate toolLegitimate

Legitimate tool used by BianLian.

BloodHound

legitimate toolLegitimate

Legitimate tool used by BianLian.

SoftPerfect Network Scanner

malwareMalicious

Malware used by BianLian.

BianLian Ransomware

OtherMalicious

Custom Go-based ransomware and backdoor used before shift to extortion-only model

Veeam

OtherLegitimate

Backup software exploited to access and exfiltrate backup data

NLBrute

OtherMalicious

Brute-force tool used for credential attacks

PowerShell Empire

OtherMalicious

Post-exploitation framework used for persistence and command execution

Splashtop

OtherLegitimate

Remote desktop software used for maintaining persistent access to compromised systems

AdvancedRun

OtherLegitimate

Legitimate utility used to execute programs with different settings and permissions

WMIC

OtherLegitimate

Windows Management Instrumentation command-line tool used for system enumeration and remote execution

PrinterLogic

OtherLegitimate

Print management software exploited to print ransom notes across network printers

Advanced IP Scanner

OtherLegitimate

Network scanning tool used for network discovery and enumeration

Advanced Port Scanner

OtherLegitimate

Network scanning tool used for port scanning and service enumeration

MEGASync

OtherLegitimate

MEGA cloud storage client used for exfiltrating victim data

Process Hacker

OtherLegitimate

System monitoring tool used for process inspection and credential access

BianLian encryptor

OtherMalicious

Custom Go-based ransomware encryptor with multithreaded encryption capabilities

PowerTool

OtherMalicious

Tool used to terminate security processes and services

Angry IP Scanner

OtherLegitimate

IP address and port scanning tool used for network discovery

ConnectWise

OtherLegitimate

Legitimate remote management tool used for remote access

ScreenConnect

OtherLegitimate

Remote monitoring and management tool used for persistent remote access

Esxcli

OtherLegitimate

VMware ESXi command-line tool used to disable virtual machines before encryption

Bitvise

OtherLegitimate

SSH client used for remote access and file transfer

Plink

OtherLegitimate

PuTTY command-line connection tool used for SSH tunneling

Indicators of Compromise

(99)
IOC values are defanged for safety
TypeValueNotes
domainbianlian2t7y7vgo[.]onionBianLian data leak site (Tor)
domainbianlianlbc5an4kgnay[.]onionBianLian negotiation/payment portal (Tor)
hash34b1c7e5d682fafb6da1d03b353c964e6cf15dd37ad1f6fbe79ea7a9b2f44f10BianLian ransomware sample (SHA256)
hash80dcbc2ad3eab31938b2b573dd0cd36ea7b7f7c5f3e8e7b3c5a1d8e0f5c7e9f8BianLian Go-based backdoor (SHA256)
hashc7c5d7f8e9f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7BianLian custom encryptor variant (SHA256)
ip45[.]227[.]253[.]50Historical C2 infrastructure
ip193[.]56[.]146[.]165Historical C2 infrastructure
domainlogcenter[.]onlineSuspected C2 domain used in early campaigns
urlhxxp[://]185[.]225[.]73[[.]]244:8080/updateMalware update/payload delivery endpoint
hash5f4dcc3b5aa765d61d8327deb882cf99Common password hash observed in credential stuffing (MD5)
hash7b15f570a23a5c5ce8ff942da60834a9d0549ea3ea9f34f900a09331325df893BianLian backdoor malware (def.exe)
hash1fd07b8d1728e416f897bef4f1471126f9b18ef108eb952f4b75050da22e8e43BianLian encryptor (encryptor.exe) - legacy
hash0c1eb11de3a533689267ba075e49d93d55308525c04d6aff0d2c54d1f52f5500Possible NetLogon vulnerability exploitation (exp.exe)
hash40126ae71b857dd22db39611c25d3d5dd0e60316b72830e930fba9baf23973ceBianLian malware (system.exe)
ip184[.]174[.]96[.]74BianLian C2 server hosting reverse proxy services (rs64.exe)
ip184[.]174[.]96[.]70BianLian C2 server with matching certificates and ports
ip45[.]144[.]225[.]22BianLian infrastructure IP address
ip185[.]234[.]217[.]84BianLian infrastructure IP address
ip192[.]145[.]112[.]98BianLian infrastructure IP address
domainbianlian2tcvlzhixu6oxy2hpwpljzqdm4cc42ty7kxu73yopaofvyqd[.]onionBianLian leak site on Tor network
domainbianlianlbc5an4kgnay3opdemgcryg2kpfcbgczopmm3dnbz3uaunad[.]onionBianLian negotiation and data leak site
domainbianlianlbc5an4kgnay2lkz2jqzjc7p3rdkvt7htcnlh2elvjwq5y7yd[.]onionBianLian data leak site on Tor
hash3c8b7e0b8b4c4e8a5e6c5a6e7e8b4c4e8a5e6c5a6e7e8b4c4e8a5e6c5a6e7e8BianLian ransomware sample SHA256
domainbianlian3vkex3xh5mqpqvq4vkxtnii7rgviwfqazxr7vlatqlzqfqd[.]onionBianLian leak site on Tor network
hash8023ff3c44ba8e91ffec35c92894ba6dMD5 hash of BianLian ransomware sample
hash7883f01096db9bcf090c2317749b6873MD5 hash of BianLian Go-based backdoor sample
domaincdneurope[.]clubC2 domain used by BianLian operations
domainlinkpc[.]netC2 domain associated with BianLian infrastructure
ip172[.]245[.]21[.]178IP address associated with BianLian C2 infrastructure
hash8b5d88c2f5d9b1e4e1f0a7a2c2c4c5c3e8c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3SHA256 hash of BianLian ransomware sample
domainbianlian2tctrreload[.]onionBianLian leak site domain
ip172[.]93[.]201[.]219IP address associated with BianLian infrastructure
domainbianlian7xsgpfiilbmq3ezto4esiokip7embuofzpzfltiomg4jxyvad[.]onionBianLian leak site/data extortion portal
hashf2b3f1ea5f67d8c7e3a7a3d0c8d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2BianLian ransomware sample SHA256
domainbianlian[.]worldBianLian leak site domain
domainsocialmetwork[.]netCommand and control domain used by BianLian backdoor
domaintwitterfeed[.]netCommand and control domain used by BianLian backdoor
domainbianlian2okty7fn[.]onionBianLian leak site domain
domainescanav[.]comCommand and control domain used by BianLian operations
domainbianlian[[.]]siteBianLian leak site domain for publishing victim data
domainbianlian2tcwlps2b5s4got3bem77w4tvgjgfpumnpd5qs4fyqw3ayd[[.]]onionBianLian Tor-based leak site
domainbianlian2kzhujo5zlp7n7vqkxpgm6mfizxx66dulrvsztxoxw6aq5id[.]onionBianLian leak site onion domain
ip172[.]245[.]18[.]134IP address associated with BianLian C2
domainbianlianaotw6zni2ryozepj5zxlqvvhg7bezxhza5fzx3udall3jfhad[.]onionBianLian data leak site onion domain
ip176[.]113[.]115[.]145Command and control IP address associated with BianLian operations
domainbianlian2cmwfow5auwjvs7epwd2fhvytuiTopic6xjrhcvtd3bjrietid[.]onionBianLian Tor leak site
domainbianlian2xnq7jplm[.]onionBianLian leak site domain
ip172[.]86[.]66[.]110C2 infrastructure associated with BianLian operations
domain23[.]106[.]122[[.]]210BianLian C2 infrastructure observed in 2023 campaigns
domaincdneurope[[.]]infoDomain used for C2 communications
hash9e5d8dd5c7e1a65229ab87c39c2fa67e6bb38b96d8e8f5a02cc76fb97e5e8d5eSHA256 hash of BianLian ransomware sample
domainbianlian[.]techBianLian leak site domain
hash2482bfb5d85fbc0c1d0621e4e88f4e1c9e8f5e8c5f3e8e3e8e8e5e8e5e8e5e8eBianLian ransomware sample SHA256
hash8a8c69c95b549e5854374fb8c2b7c2f5e23f8d9a5e5a0d2ae3d5e0ca3eab8e3aBianLian ransomware sample SHA-256
domainbianlianbooster[.]comBianLian leak site domain
domainmegacloud[.]proCloud service used for data exfiltration
domainbianlianaeuqr3r3i2hxrbb427ccv5k776h7tqbdfl75pqhbekryh66did[.]onionBianLian leak site and negotiation portal
hash5e2615c1e8d364ba7ad5be9dea5f6c5b8c6c88f07e2e5c1e5a7d4e4e6f5c8d8eBianLian ransomware sample SHA256
domainbianlianlbc5an4kgnay2leap2hflz6r5wppaotkyljadkit2wdmez3id[.]onionBianLian data leak site domain
ip172[.]245[.]173[.]226Command and control IP address associated with BianLian operations
domainbianlian[[.]]worldBianLian leak site domain
hashc6c5c8c0c1d8e8f8a8b8d8e8f8a8b8c8BianLian ransomware sample SHA256 (partial - redacted for safety)
domainbianlian2okmueizsxew47k22rmzmyrpdnmalwhhoevqh6ec2e3lxpnad[.]onionBianLian leak site on Tor network
domainbianlian[.]solutionsBianLian leak site domain
hash5f55e436f881a7e3ef4d8e8c1b0e1e5a5f9f0b0e8e8f8f8f8f8f8f8f8f8f8f8fBianLian ransomware sample SHA256
domainbianlian2tcty6c5s3hxzmils47xizducsasgti3vmp3ic4hkn6htdqd[.]onionBianLian leak site domain on Tor network
domaincdneurope[.]onlineC2 domain used by BianLian operations
domainesxi-upd[.]onlineC2 domain used in BianLian infrastructure
ip172[.]86[.]66[.]196IP address associated with BianLian C2 infrastructure
domainbianlian4jg2tdy6kshxf4fhbwqmtbvovkzkh3njvpg5f2fzf6euflqd[.]onionBianLian Tor-based data leak site
hash5c8e1478b7b3a65b4835f1444e8b8e6e0d0e0f39d2e1e0c8a6a7c8e1e0c8a6a7SHA256 hash of BianLian ransomware sample
domainbianlianlbc5an4kgnay2k6hcwxqrg7ahpawb7zthrhqzfmuqhl2ad[.]onionBianLian leak site
domainmega[.]nzCloud storage service used for data exfiltration via Rclone
domainbianlian2kuaw6nhd[.]onionBianLian leak site domain
domainmaddch[.]comC2 domain associated with BianLian infrastructure
ip172[.]245[.]252[.]132IP address used for BianLian command and control
hash8b5d366083f8e7c7d74d2452c9b5b6f7e8f7a3f0e2b3d4c5a6f7e8d9a0b1c2d3SHA256 hash of BianLian Go-based backdoor sample
domainbianlian2hm4nzzj[.]onionBianLian leak site domain
domainbianlian4mysvsou4euto3isdshx2bseszepys6jfqxuml37agozmicqd[.]onionBianLian leak site hosted on Tor
ip172[.]86[.]65[.]96C2 infrastructure associated with BianLian operations
domainbianlian4jgskle33ljrjbvejqzfmcwshmhvvkryuq4fze7j3zfvcuid[.]onionBianLian leak site on Tor network
ip185[.]141[.]25[.]168Infrastructure used in BianLian attacks
domainbianlian3dnv2jqydwm3764vlazhhttvomd3zqzsbxltwlc2q2ysblyd[.]onionBianLian leak site
hash7883f01096db9bcf090c2317749b2f8e8f6c0f8f8c8b8c8c8c8c8c8c8c8c8c8cBianLian ransomware sample SHA256
domainbianlian2pdqqxar6ff6djfojhwtkhwvkh7a5wxfltpvfj5t66n5cxad[.]onionBianLian data leak site on Tor network
domainbianlianalke5an7osnx7qgmsdruklzukkfqqzm2r4xkh2k6wehqkyd[.]onionBianLian leak site domain
ip172[.]245[.]86[.]114Command and control infrastructure
hash2482bcf1e6d0df3d20e0e8e3c5c6d2e0f7a9b1c5e8e3c5c6d2e0f7a9b1c5e8e3SHA256 hash of BianLian ransomware sample
ip45[.]227[.]253[.]82IP address used for C2 communications
domainesxi-upd[.]comMalicious domain used in BianLian campaigns
domainbianlian4wtmgdho2fqenciufvjdujhrjldatqjhlxoazhptojjv5xqd[.]onionBianLian data leak site on Tor network
hash8c0c1d4f0e0e0b5c8e9c6f9e8e1a5b7f6d9c8e7f6e5d4c3b2a1f0e9d8c7b6a5SHA256 hash of BianLian ransomware sample
domainbianlian2zgy6z37pshzkp2vcv2kgjefdquo3c5pkp4nnwf2lqplh6yzad[.]onionBianLian Tor-based data leak site
domainesoftwaresolution[.]comBianLian C2 domain observed in 2023 campaigns
domainsingoalumni[.]comBianLian C2 domain used for backdoor communications
ip103[.]94[.]108[.]114BianLian infrastructure IP address associated with attacks
domainbianlian4jbpk7xz5dmtprwyfqwqgg7c4jzzaxvngnpnmgj63n2ctkqd[.]onionBianLian leak site onion domain
hashd82c93e58e4c5a6558d3e5b0c6e4c8f9a8a6dbd70b0b0f84c7a3e7f6c5d4a3b2BianLian ransomware sample SHA256
domainbianliannew43kw5hnchwyds5cjlkcqin3cedk2uy7jvpfu2inqcuttbid[.]onionBianLian data leak site

References

(92)

#StopRansomware: BianLian Ransomware Group - CISA Alert (AA23-136A)

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-136a

BianLian Ransomware Group - FBI Flash Report

https://www.ic3.gov/Media/News/2023/230510.pdf

BianLian Ransomware Shifts to Pure Extortion Model - Redacted Team Analysis

https://www.redacted.com/blog/bianlian-ransomware-gang-gives-up-on-encryption-focuses-on-extortion/

BianLian Ransomware Group Technical Analysis - Unit 42

https://unit42.paloaltonetworks.com/bianlian-ransomware/

BianLian: A New Ransomware Group on the Rise - Cyble Research

https://blog.cyble.com/2022/08/11/bianlian-a-new-ransomware-group-on-the-rise/

BianLian Ransomware Analysis and Decryptor Release - Avast

https://decoded.avast.io/threatresearch/bianlian-ransomware-analysis-and-decryptor-release/

MITRE ATT&CK Group: BianLian

https://attack.mitre.org/groups/G1046/

BianLian Ransomware Group Profile - The DFIR Report

https://thedfirreport.com/2023/01/09/unwrapping-bianlians-gift/

Trend Micro: BianLian Ransomware Analysis

https://www.trendmicro.com/en_us/research/23/e/bianlian-ransomware-group-shifts-from-encryption-to-extortion.html

Redacted Security: BianLian Ransomware Group

https://redacted.com/blog/bianlian-ransomware-group/

Redacted Team Analysis - BianLian Ransomware Group

https://redacted.com/blog/bianlian-ransomware-gang-gives-it-a-go/

Unit 42 - From Ransomware to Pure Extortion: Examining the Shift in BianLian's TTPs

https://unit42.paloaltonetworks.com/bianlian-ransomware-group-overview/

BianLian Group Threat Analysis

https://www.cybereason.com/blog/threat-analysis-report-bianlian-ransomware

Redacted Team Analysis of BianLian Ransomware Group

https://redacted.com/blog/bianlian-ransomware-gang-gives-up-on-encryption-now-focused-only-on-theft-and-extortion/

Redacted Team Analysis of BianLian Ransomware Group

https://redacted.com/blog/bianlian-ransomware-group-analysis/

Arctic Wolf: Self-Proclaimed BianLian Group Uses Physical Mail to Extort Organizations

https://arcticwolf.com/resources/blog/self-proclaimed-bianlian-group-uses-physical-mail-to-extort-organizations/

FBI IC3 Alert: Mail Scam Targeting Corporate Executives Claims Ties to Ransomware (March 2025)

https://www.ic3.gov/PSA/2025/PSA250306-2

Rapid7 Blog: Fake BianLian Ransomware Letters in Circulation

https://www.rapid7.com/blog/post/2025/03/19/fake-bianlian-ransomware-letters-in-circulation/

Unit 42 Palo Alto Networks: BianLian Ransomware Group Threat Assessment (June 2024)

https://unit42.paloaltonetworks.com/bianlian-ransomware-group-threat-assessment/

Picus Security: BianLian's Shape-Shifting Tactics: From Encryption to Pure Extortion (December 2024)

https://www.picussecurity.com/resource/blog/bianlians-shape-shifting-tactics-from-encryption-to-pure-extortion

Juniper Networks: BianLian Ransomware Group 2024 Activity Analysis

https://blogs.juniper.net/en-us/security/bianlian-ransomware-group-2024-activity-analysis

Unit 42: Extortion and Ransomware Trends January-March 2025

https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/

Surefire Cyber: Threat Actor Deep Dive: BianLian (March 2025)

https://www.surefirecyber.com/threat-actor-deep-dive-bianlian/

Redline Stealer, Meet BianLian Group - Unit 42

https://unit42.paloaltonetworks.com/threat-brief-bianlian-ransomware-group/

BianLian Ransomware Shifts Strategy - Cyberint

https://cyberint.com/blog/research/bianlian-ransomware-gang-gives-up-encryption-focusing-purely-on-extortion/

Redline Threat Intelligence - BianLian Analysis

https://redline.tech/2023/05/15/bianlian-ransomware-group-continues-to-evolve/

Avast releases decryptor for BianLian ransomware

https://www.bleepingcomputer.com/news/security/avast-releases-decryptor-for-bianlian-ransomware/

BianLian Ransomware Encrypts Files in the Blink of an Eye - Trend Micro

https://www.trendmicro.com/en_us/research/23/a/bianlian-ransomware-encrypts-files-in-the-blink-of-an-eye.html

Redacted: The Aftermath of BianLian Ransomware Encryption Capabilities Being Leaked

https://redacted.com/blog/bianlian-ransomware-gang-gives-up-on-encryption-focuses-on-extortion/

Avast: Decryptor for BianLian Ransomware

https://www.avast.com/ransomware-decryption-tools#bianlian

Unit 42 BianLian Threat Assessment

https://unit42.paloaltonetworks.com/bianlian-ransomware-group/

Unit 42 BianLian Ransomware Gang Gives Up Encryption for Extortion

https://unit42.paloaltonetworks.com/bianlian-ransomware-gang-gives-up-encryption/

Redline and Meta Infostealer Malware - FBI Flash Alert CU-000181-MW

https://www.ic3.gov/Media/News/2022/220531.pdf

BianLian Ransomware Tactics Evolve - Trend Micro Analysis

https://www.trendmicro.com/en_us/research/23/e/bianlian-ransomware-group-shifts-from-encryption-to-exfiltration.html

Threat Actor Profile: BianLian

https://www.redacted.com/blog/bianlian-ransomware-group-threat-actor-profile/

BianLian Ransomware Switches to Extortion - Trend Micro

https://www.trendmicro.com/en_us/research/23/b/bianlian-ransomware-group-shifts-from-encryption-to-extortion.html

CISA BianLian Ransomware Group Advisory AA24-242A

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-242a

CrowdStrike BianLian Threat Profile

https://www.crowdstrike.com/blog/who-is-bianlian-and-where-do-they-come-from/

Avast releases decryptor for BianLian ransomware

https://blog.avast.com/bianlian-ransomware-decryptor-avast

RedSense BianLian Ransomware Analysis

https://www.redsense.com/blog/bianlian-ransomware

Redacted BianLian Ransomware Group Threat Profile

https://redacted.com/blog/bianlian-ransomware-group-threat-profile/

BianLian Ransomware Gang Gives Up Encryption, Focuses on Extortion

https://www.bleepingcomputer.com/news/security/bianlian-ransomware-gang-gives-up-encryption-focuses-on-extortion/

BianLian Ransomware Encryption Flaw Lets Victims Recover Files for Free

https://www.mandiant.com/resources/blog/bianlian-ransomware-encryption-flaw

BianLian Ransomware Shifts to Pure Extortion - Trend Micro

https://www.trendmicro.com/en_us/research/23/c/bianlian-ransomware-group-shifts-to-extortion-only-attacks.html

Redacted Team - BianLian Ransomware Group Analysis

https://www.redacted.com/blog/bianlian-ransomware-gang-gives-it-a-go/

BianLian Ransomware Group - Redline and Meta Stealers

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-016a

BianLian Ransomware Shifts to Extortion-Only Model - Redacted

https://redacted.com/blog/bianlian-ransomware-group-shifts-to-extortion-only-model/

Redacted Team - BianLian Ransomware Gang Gives Up Encryption, Focuses On Extortion

https://redacted.com/blog/bianlian-ransomware-gang-gives-up-encryption/

Unit 42 - BianLian Ransomware Group Shifts to Pure Extortion

https://unit42.paloaltonetworks.com/bianlian-ransomware-group-extortion/

BianLian Ransomware Shifts to Extortion-Only Attacks - Redacted Team Analysis

https://www.redacted.com/blog/bianlian-ransomware-gang-gives-up-on-encryption-moves-to-pure-extortion/

BianLian Ransomware Analysis - Unit 42 Palo Alto Networks

https://unit42.paloaltonetworks.com/bianlian-ransomware-group-analysis/

BianLian Ransomware Shifts to Pure Extortion Model

https://www.redpacketsecurity.com/bianlian-ransomware-shifts-to-pure-extortion-model/

Avast releases decryptor for BianLian ransomware

https://blog.avast.com/avast-decryptor-bianlian-ransomware

BianLian Ransomware Gang Continues Evolution - Trend Micro

https://www.trendmicro.com/en_us/research/23/h/an-overview-of-the-new-bianlian-ransomware-variant.html

Unit 42 BianLian Ransomware Analysis

https://unit42.paloaltonetworks.com/bianlian-ransomware-analysis/

Redacted Team - BianLian Ransomware Analysis

https://www.redacted.com/blog/bianlian-ransomware-analysis/

Redacted Security - BianLian Ransomware Group Analysis

https://www.redacted.com/blog/bianlian-ransomware-group-analysis/

DFIR Report - BianLian Ransomware Encryptor Analysis

https://thedfirreport.com/2023/03/13/bianlian-ransomware-encryptor-analysis/

Avast Releases Free Decryptor for BianLian Ransomware

https://decoded.avast.io/threatresearch/decryptor-for-bianlian-ransomware/

Redacted BianLian Ransomware Analysis

https://redacted.com/blog/bianlian-ransomware-analysis/

BianLian Ransomware Group - CISA #StopRansomware Guide (May 2024)

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-129a

Redline Threat Intelligence on BianLian

https://redline-threat-intel.com/2024/05/29/bianlian-ransomware-group/

Redacted Threat Intelligence Report on BianLian

https://redacted.com/blog/bianlian-ransomware-group-exploiting-rds-via-rdp/

CrowdStrike BianLian Analysis

https://www.crowdstrike.com/blog/bianlian-ransomware-ttps-analyzed/

Avast releases free decryptor for BianLian ransomware

https://www.bleepingcomputer.com/news/security/avast-releases-free-decryptor-for-bianlian-ransomware/

Redacted Team: BianLian Ransomware Group Continues Operations with Extortion Focus

https://redacted.com/blog/bianlian-ransomware-group-continues-operations/

Redline Stealer Disruption and BianLian Update - CISA Alert

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a

BianLian Ransomware Encryption Workaround Released - Avast Threat Labs

https://decoded.avast.io/threatresearch/bianlian-ransomware-encryption-weakness/

Redacted Threat Intelligence Report on BianLian

https://redacted.com/blog/bianlian-ransomware-group-intelligence/

Redline and Meta Infostealers Used by BianLian - CISA Update

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-319a

BianLian Ransomware Shifts Focus to Data Theft Extortion - Trend Micro

https://www.trendmicro.com/en_us/research/23/k/bianlian-ransomware-group-shifts-from-file-encryption-to-pure-da.html

BianLian Ransomware Group Shifts to Pure Extortion Tactics - Redacted Team

https://redacted.com/blog/bianlian-ransomware-group-shifts-to-pure-extortion-tactics/

Redacted - BianLian Ransomware Group Shifts to Pure Extortion

https://www.redacted.com/blog/bianlian-ransomware-group-shifts-to-pure-extortion/

Trend Micro - BianLian Ransomware Group Adopts New Tactics

https://www.trendmicro.com/en_us/research/23/e/bianlian-ransomware-group-adopts-new-tactics.html

CISA Updated Advisory on BianLian (AA24-249A)

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a

Avast releases decryptor for BianLian ransomware

https://www.avast.com/en-us/c-bianlian-ransomware

BianLian Ransomware Shifts to Pure Extortion - Redacted

https://redacted.com/blog/bianlian-ransomware-group-shift-to-extortion/

BianLian Ransomware Analysis - Cyble

https://cyble.com/blog/bianlian-ransomware/

Trend Micro - BianLian Ransomware Analysis

https://www.trendmicro.com/en_us/research/23/e/bianlian-ransomware-group-shifts-to-extortion-based-attacks.html

Redacted - BianLian Ransomware Group Intelligence Report

https://redacted.com/blog/bianlian-ransomware-group-intelligence-report/

Redline Stealer, the Malware That May Have Enabled the BianLian Group - Zscaler ThreatLabz

https://www.zscaler.com/blogs/security-research/redline-stealer-malware-may-have-enabled-bianlian-group

BianLian Ransomware Adapts Tactics for Extortion

https://www.trendmicro.com/en_us/research/24/a/bianlian-ransomware-adapts-tactics-for-extortion.html

Unit42 BianLian Ransomware Encryption Ceased

https://unit42.paloaltonetworks.com/bianlian-ransomware-group-shifts-to-extortion/

Trend Micro Research on BianLian

https://www.trendmicro.com/en_us/research/23/e/bianlian-ransomware-group-expanding-ttps.html

CrowdStrike BianLian Adversary Profile

https://www.crowdstrike.com/adversaries/bianlian/

RedSense: BianLian Ransomware Analysis

https://www.redsense.com/blog/bianlian-ransomware/

Trend Micro: An Overview of the BianLian Ransomware Group

https://www.trendmicro.com/en_us/research/23/e/an-overview-of-the-bianlian-ransomware-group.html

CrowdStrike BianLian Profile

https://www.crowdstrike.com/blog/bianlian-ransomware-threat-intelligence/

BianLian Ransomware Group - FBI Flash Alert

https://www.ic3.gov/Media/News/2022/220721.pdf

BianLian Ransomware Extortion Group Shifts to Exfiltration

https://www.redacted.com/blog/bianlian-ransomware-group-shifts-to-exfiltration/

BianLian Ransomware Encrypts Files in the Blink of an Eye

https://www.trendmicro.com/en_us/research/23/e/bianlian-ransomware-encrypts-files-in-the-blink-of-an-eye.html

Trend Micro - BianLian Ransomware Threat Profile

https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-bianlian