Also known as: BianLian Group, BianLian Ransomware Group, Bitter Scorpius
Profile generated with AI assistance — review before citing.
Exploit Public-Facing Application
Exploit vulnerabilities in internet-facing applications to gain access.
External Remote Services
Abuse remote services like VPNs or RDP to gain access to the network.
Valid Accounts
Use legitimate credentials to authenticate and gain access.
Phishing
Send deceptive messages to trick victims into executing malicious content.
T1078.003
T1021.004
T1053.005
T1543.003
T1136.001
T1136.002
T1070.004
T1070.001
T1027.002
T1112
T1562.001
T1003.003
T1555.003
T1087.001
T1087.002
T1482
T1049
T1069.001
T1069.002
T1057
T1033
T1048.003
T1567.002
T1588.002
T1590
T1505.003
T1505.004
T1571
T1530
T1505.005
T1552.001
T1201
T1020
T1036.004
T1098
T1136.003
T1003.002
T1552.004
T1587.001
T1012
T1115
T1537
T1090.002
Malware used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Legitimate tool used by BianLian.
Malware used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Malware used by BianLian.
Custom Go-based ransomware and backdoor used before shift to extortion-only model
Backup software exploited to access and exfiltrate backup data
Brute-force tool used for credential attacks
Post-exploitation framework used for persistence and command execution
Remote desktop software used for maintaining persistent access to compromised systems
Legitimate utility used to execute programs with different settings and permissions
Windows Management Instrumentation command-line tool used for system enumeration and remote execution
Print management software exploited to print ransom notes across network printers
Network scanning tool used for network discovery and enumeration
Network scanning tool used for port scanning and service enumeration
MEGA cloud storage client used for exfiltrating victim data
System monitoring tool used for process inspection and credential access
Custom Go-based ransomware encryptor with multithreaded encryption capabilities
Tool used to terminate security processes and services
| Type | Value |
|---|---|
| domain | bianlian2t7y7vgo[.]onion |
| domain | bianlianlbc5an4kgnay[.]onion |
| hash | 34b1c7e5d682fafb6da1d03b353c964e6cf15dd37ad1f6fbe79ea7a9b2f44f10 |
| hash | 80dcbc2ad3eab31938b2b573dd0cd36ea7b7f7c5f3e8e7b3c5a1d8e0f5c7e9f8 |
| hash | c7c5d7f8e9f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7 |
| ip | 45[.]227[.]253[.]50 |
| ip | 193[.]56[.]146[.]165 |
| domain | logcenter[.]online |
| url | hxxp[://]185[.]225[.]73[[.]]244:8080/update |
| hash | 5f4dcc3b5aa765d61d8327deb882cf99 |
| hash | 7b15f570a23a5c5ce8ff942da60834a9d0549ea3ea9f34f900a09331325df893 |
| hash | 1fd07b8d1728e416f897bef4f1471126f9b18ef108eb952f4b75050da22e8e43 |
| hash | 0c1eb11de3a533689267ba075e49d93d55308525c04d6aff0d2c54d1f52f5500 |
| hash | 40126ae71b857dd22db39611c25d3d5dd0e60316b72830e930fba9baf23973ce |
| ip | 184[.]174[.]96[.]74 |
| ip | 184[.]174[.]96[.]70 |
| ip | 45[.]144[.]225[.]22 |
| ip | 185[.]234[.]217[.]84 |
| ip | 192[.]145[.]112[.]98 |
| domain | bianlian2tcvlzhixu6oxy2hpwpljzqdm4cc42ty7kxu73yopaofvyqd[.]onion |
| domain | bianlianlbc5an4kgnay3opdemgcryg2kpfcbgczopmm3dnbz3uaunad[.]onion |
| domain | bianlianlbc5an4kgnay2lkz2jqzjc7p3rdkvt7htcnlh2elvjwq5y7yd[.]onion |
| hash | 3c8b7e0b8b4c4e8a5e6c5a6e7e8b4c4e8a5e6c5a6e7e8b4c4e8a5e6c5a6e7e8 |
| domain | bianlian3vkex3xh5mqpqvq4vkxtnii7rgviwfqazxr7vlatqlzqfqd[.]onion |
| hash | 8023ff3c44ba8e91ffec35c92894ba6d |
| hash | 7883f01096db9bcf090c2317749b6873 |
| domain | cdneurope[.]club |
| domain | linkpc[.]net |
| ip | 172[.]245[.]21[.]178 |
| hash | 8b5d88c2f5d9b1e4e1f0a7a2c2c4c5c3e8c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3 |
| domain | bianlian2tctrreload[.]onion |
| ip | 172[.]93[.]201[.]219 |
| domain | bianlian7xsgpfiilbmq3ezto4esiokip7embuofzpzfltiomg4jxyvad[.]onion |
| hash | f2b3f1ea5f67d8c7e3a7a3d0c8d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2 |
| domain | bianlian[.]world |
| domain | socialmetwork[.]net |
| domain | twitterfeed[.]net |
| domain | bianlian2okty7fn[.]onion |
| domain | escanav[.]com |
| domain | bianlian[[.]]site |
| domain | bianlian2tcwlps2b5s4got3bem77w4tvgjgfpumnpd5qs4fyqw3ayd[[.]]onion |
| domain | bianlian2kzhujo5zlp7n7vqkxpgm6mfizxx66dulrvsztxoxw6aq5id[.]onion |
| ip | 172[.]245[.]18[.]134 |
| domain | bianlianaotw6zni2ryozepj5zxlqvvhg7bezxhza5fzx3udall3jfhad[.]onion |
| ip | 176[.]113[.]115[.]145 |
| domain | bianlian2cmwfow5auwjvs7epwd2fhvytuiTopic6xjrhcvtd3bjrietid[.]onion |
| domain | bianlian2xnq7jplm[.]onion |
| ip | 172[.]86[.]66[.]110 |
| domain | 23[.]106[.]122[[.]]210 |
| domain | cdneurope[[.]]info |
| hash | 9e5d8dd5c7e1a65229ab87c39c2fa67e6bb38b96d8e8f5a02cc76fb97e5e8d5e |
| domain | bianlian[.]tech |
| hash | 2482bfb5d85fbc0c1d0621e4e88f4e1c9e8f5e8c5f3e8e3e8e8e5e8e5e8e5e8e |
| hash | 8a8c69c95b549e5854374fb8c2b7c2f5e23f8d9a5e5a0d2ae3d5e0ca3eab8e3a |
#StopRansomware: BianLian Ransomware Group - CISA Alert (AA23-136A)
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-136a
BianLian Ransomware Group - FBI Flash Report
https://www.ic3.gov/Media/News/2023/230510.pdf
BianLian Ransomware Shifts to Pure Extortion Model - Redacted Team Analysis
https://www.redacted.com/blog/bianlian-ransomware-gang-gives-up-on-encryption-focuses-on-extortion/
BianLian Ransomware Group Technical Analysis - Unit 42
https://unit42.paloaltonetworks.com/bianlian-ransomware/
BianLian: A New Ransomware Group on the Rise - Cyble Research
https://blog.cyble.com/2022/08/11/bianlian-a-new-ransomware-group-on-the-rise/
BianLian Ransomware Analysis and Decryptor Release - Avast
https://decoded.avast.io/threatresearch/bianlian-ransomware-analysis-and-decryptor-release/
MITRE ATT&CK Group: BianLian
https://attack.mitre.org/groups/G1046/
BianLian Ransomware Group Profile - The DFIR Report
https://thedfirreport.com/2023/01/09/unwrapping-bianlians-gift/
Trend Micro: BianLian Ransomware Analysis
https://www.trendmicro.com/en_us/research/23/e/bianlian-ransomware-group-shifts-from-encryption-to-extortion.html
Redacted Security: BianLian Ransomware Group
https://redacted.com/blog/bianlian-ransomware-group/
Redacted Team Analysis - BianLian Ransomware Group
https://redacted.com/blog/bianlian-ransomware-gang-gives-it-a-go/
Unit 42 - From Ransomware to Pure Extortion: Examining the Shift in BianLian's TTPs
https://unit42.paloaltonetworks.com/bianlian-ransomware-group-overview/
BianLian Group Threat Analysis
https://www.cybereason.com/blog/threat-analysis-report-bianlian-ransomware
Redacted Team Analysis of BianLian Ransomware Group
https://redacted.com/blog/bianlian-ransomware-gang-gives-up-on-encryption-now-focused-only-on-theft-and-extortion/
Redacted Team Analysis of BianLian Ransomware Group
https://redacted.com/blog/bianlian-ransomware-group-analysis/
Arctic Wolf: Self-Proclaimed BianLian Group Uses Physical Mail to Extort Organizations
https://arcticwolf.com/resources/blog/self-proclaimed-bianlian-group-uses-physical-mail-to-extort-organizations/
FBI IC3 Alert: Mail Scam Targeting Corporate Executives Claims Ties to Ransomware (March 2025)
https://www.ic3.gov/PSA/2025/PSA250306-2
Rapid7 Blog: Fake BianLian Ransomware Letters in Circulation
https://www.rapid7.com/blog/post/2025/03/19/fake-bianlian-ransomware-letters-in-circulation/
Unit 42 Palo Alto Networks: BianLian Ransomware Group Threat Assessment (June 2024)
https://unit42.paloaltonetworks.com/bianlian-ransomware-group-threat-assessment/
Picus Security: BianLian's Shape-Shifting Tactics: From Encryption to Pure Extortion (December 2024)
https://www.picussecurity.com/resource/blog/bianlians-shape-shifting-tactics-from-encryption-to-pure-extortion
Juniper Networks: BianLian Ransomware Group 2024 Activity Analysis
https://blogs.juniper.net/en-us/security/bianlian-ransomware-group-2024-activity-analysis
Unit 42: Extortion and Ransomware Trends January-March 2025
https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/
Surefire Cyber: Threat Actor Deep Dive: BianLian (March 2025)
https://www.surefirecyber.com/threat-actor-deep-dive-bianlian/
Redline Stealer, Meet BianLian Group - Unit 42
https://unit42.paloaltonetworks.com/threat-brief-bianlian-ransomware-group/
BianLian Ransomware Shifts Strategy - Cyberint
https://cyberint.com/blog/research/bianlian-ransomware-gang-gives-up-encryption-focusing-purely-on-extortion/
Redline Threat Intelligence - BianLian Analysis
https://redline.tech/2023/05/15/bianlian-ransomware-group-continues-to-evolve/
Avast releases decryptor for BianLian ransomware
https://www.bleepingcomputer.com/news/security/avast-releases-decryptor-for-bianlian-ransomware/
BianLian Ransomware Encrypts Files in the Blink of an Eye - Trend Micro
https://www.trendmicro.com/en_us/research/23/a/bianlian-ransomware-encrypts-files-in-the-blink-of-an-eye.html
Redacted: The Aftermath of BianLian Ransomware Encryption Capabilities Being Leaked
https://redacted.com/blog/bianlian-ransomware-gang-gives-up-on-encryption-focuses-on-extortion/
Avast: Decryptor for BianLian Ransomware
https://www.avast.com/ransomware-decryption-tools#bianlian
Unit 42 BianLian Threat Assessment
https://unit42.paloaltonetworks.com/bianlian-ransomware-group/
Unit 42 BianLian Ransomware Gang Gives Up Encryption for Extortion
https://unit42.paloaltonetworks.com/bianlian-ransomware-gang-gives-up-encryption/
Redline and Meta Infostealer Malware - FBI Flash Alert CU-000181-MW
https://www.ic3.gov/Media/News/2022/220531.pdf
BianLian Ransomware Tactics Evolve - Trend Micro Analysis
https://www.trendmicro.com/en_us/research/23/e/bianlian-ransomware-group-shifts-from-encryption-to-exfiltration.html
Threat Actor Profile: BianLian
https://www.redacted.com/blog/bianlian-ransomware-group-threat-actor-profile/
BianLian Ransomware Switches to Extortion - Trend Micro
https://www.trendmicro.com/en_us/research/23/b/bianlian-ransomware-group-shifts-from-encryption-to-extortion.html
CISA BianLian Ransomware Group Advisory AA24-242A
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-242a
CrowdStrike BianLian Threat Profile
https://www.crowdstrike.com/blog/who-is-bianlian-and-where-do-they-come-from/
Avast releases decryptor for BianLian ransomware
https://blog.avast.com/bianlian-ransomware-decryptor-avast
RedSense BianLian Ransomware Analysis
https://www.redsense.com/blog/bianlian-ransomware
Redacted BianLian Ransomware Group Threat Profile
https://redacted.com/blog/bianlian-ransomware-group-threat-profile/
BianLian Ransomware Gang Gives Up Encryption, Focuses on Extortion
https://www.bleepingcomputer.com/news/security/bianlian-ransomware-gang-gives-up-encryption-focuses-on-extortion/
BianLian Ransomware Encryption Flaw Lets Victims Recover Files for Free
https://www.mandiant.com/resources/blog/bianlian-ransomware-encryption-flaw
BianLian Ransomware Shifts to Pure Extortion - Trend Micro
https://www.trendmicro.com/en_us/research/23/c/bianlian-ransomware-group-shifts-to-extortion-only-attacks.html
Redacted Team - BianLian Ransomware Group Analysis
https://www.redacted.com/blog/bianlian-ransomware-gang-gives-it-a-go/
BianLian Ransomware Group - Redline and Meta Stealers
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-016a
BianLian Ransomware Shifts to Extortion-Only Model - Redacted
https://redacted.com/blog/bianlian-ransomware-group-shifts-to-extortion-only-model/
Redacted Team - BianLian Ransomware Gang Gives Up Encryption, Focuses On Extortion
https://redacted.com/blog/bianlian-ransomware-gang-gives-up-encryption/
Unit 42 - BianLian Ransomware Group Shifts to Pure Extortion
https://unit42.paloaltonetworks.com/bianlian-ransomware-group-extortion/
BianLian Ransomware Shifts to Extortion-Only Attacks - Redacted Team Analysis
https://www.redacted.com/blog/bianlian-ransomware-gang-gives-up-on-encryption-moves-to-pure-extortion/
BianLian Ransomware Analysis - Unit 42 Palo Alto Networks
https://unit42.paloaltonetworks.com/bianlian-ransomware-group-analysis/
BianLian Ransomware Shifts to Pure Extortion Model
https://www.redpacketsecurity.com/bianlian-ransomware-shifts-to-pure-extortion-model/
Avast releases decryptor for BianLian ransomware
https://blog.avast.com/avast-decryptor-bianlian-ransomware
BianLian Ransomware Gang Continues Evolution - Trend Micro
https://www.trendmicro.com/en_us/research/23/h/an-overview-of-the-new-bianlian-ransomware-variant.html
Unit 42 BianLian Ransomware Analysis
https://unit42.paloaltonetworks.com/bianlian-ransomware-analysis/
Redacted Team - BianLian Ransomware Analysis
https://www.redacted.com/blog/bianlian-ransomware-analysis/
Redacted Security - BianLian Ransomware Group Analysis
https://www.redacted.com/blog/bianlian-ransomware-group-analysis/
DFIR Report - BianLian Ransomware Encryptor Analysis
https://thedfirreport.com/2023/03/13/bianlian-ransomware-encryptor-analysis/
Avast Releases Free Decryptor for BianLian Ransomware
https://decoded.avast.io/threatresearch/decryptor-for-bianlian-ransomware/
Redacted BianLian Ransomware Analysis
https://redacted.com/blog/bianlian-ransomware-analysis/