Also known as: BianLian Group, BianLian Ransomware Group
Profile generated with AI assistance — review before citing.
T1078.003
T1021.004
T1053.005
T1543.003
T1136.001
T1136.002
T1070.004
T1070.001
T1027.002
T1112
T1562.001
T1003.003
T1555.003
T1087.001
T1087.002
T1482
T1049
T1069.001
T1069.002
T1057
T1033
T1048.003
T1567.002
T1588.002
T1590
T1505.003
Malware used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Legitimate tool used by BianLian.
Malware used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Malware used by BianLian.
| Type | Value |
|---|---|
| domain | bianlian2t7y7vgo[.]onion |
| domain | bianlianlbc5an4kgnay[.]onion |
| hash | 34b1c7e5d682fafb6da1d03b353c964e6cf15dd37ad1f6fbe79ea7a9b2f44f10 |
| hash | 80dcbc2ad3eab31938b2b573dd0cd36ea7b7f7c5f3e8e7b3c5a1d8e0f5c7e9f8 |
| hash | c7c5d7f8e9f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7 |
| ip | 45[.]227[.]253[.]50 |
| ip | 193[.]56[.]146[.]165 |
| domain | logcenter[.]online |
| url | hxxp[://]185[.]225[.]73[[.]]244:8080/update |
| hash | 5f4dcc3b5aa765d61d8327deb882cf99 |
#StopRansomware: BianLian Ransomware Group - CISA Alert (AA23-136A)
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-136a
BianLian Ransomware Group - FBI Flash Report
https://www.ic3.gov/Media/News/2023/230510.pdf
BianLian Ransomware Shifts to Pure Extortion Model - Redacted Team Analysis
https://www.redacted.com/blog/bianlian-ransomware-gang-gives-up-on-encryption-focuses-on-extortion/
BianLian Ransomware Group Technical Analysis - Unit 42
https://unit42.paloaltonetworks.com/bianlian-ransomware/
BianLian: A New Ransomware Group on the Rise - Cyble Research
https://blog.cyble.com/2022/08/11/bianlian-a-new-ransomware-group-on-the-rise/
BianLian Ransomware Analysis and Decryptor Release - Avast
https://decoded.avast.io/threatresearch/bianlian-ransomware-analysis-and-decryptor-release/
MITRE ATT&CK Group: BianLian
https://attack.mitre.org/groups/G1046/
BianLian Ransomware Group Profile - The DFIR Report
https://thedfirreport.com/2023/01/09/unwrapping-bianlians-gift/
Trend Micro: BianLian Ransomware Analysis
https://www.trendmicro.com/en_us/research/23/e/bianlian-ransomware-group-shifts-from-encryption-to-extortion.html
Redacted Security: BianLian Ransomware Group
https://redacted.com/blog/bianlian-ransomware-group/