BianLian is a Russian-speaking ransomware and data-extortion threat actor active since at least 2022. The group is widely tracked as a financially motivated cybercriminal operation rather than a state-sponsored actor. It initially operated as a conventional ransomware enterprise combining data theft with file encryption, but after a public decryptor became available in early 2023 it shifted heavily toward extortion-only operations that emphasize exfiltration and threats to leak stolen information rather than widespread encryption. BianLian has targeted organizations across multiple sectors and geographies, including critical infrastructure, manufacturing, mining, legal services, government-related entities, healthcare-adjacent environments, and enterprises in the United States, Australia, and Latin America. Reported victimology includes high-profile extortion cases and public leak-site postings, including activity affecting Northern Minerals and claimed compromises involving major aerospace and industrial organizations. The group has also been associated with campaigns targeting Spanish-speaking organizations in Venezuela using phishing lures disguised as routine business documents. The actor commonly relies on opportunistic enterprise intrusion tradecraft. Reported initial access methods include exploitation of public-facing vulnerabilities, abuse of remote access pathways such as RDP, and misuse of remote monitoring and management software including Splashtop. BianLian has been observed exploiting JetBrains TeamCity vulnerabilities including CVE-2024-27198 and CVE-2024-27199, and has also been named among groups exploiting SAP NetWeaver flaws such as CVE-2025-31324. Once inside victim environments, the group has been associated with malware deployment, persistence through legitimate remote administration tooling, credential access, and data theft to support extortion. BianLian’s operations align with broader modern ransomware ecosystem practices: phishing, exploitation of exposed services, use of legitimate administrative tools, and pressure through leak-site publication. Reporting also links the group to frequent abuse of RDP access for reconnaissance and post-compromise activity. In some intrusions and ecosystem analyses, BianLian has been connected to shared tooling or infrastructure patterns seen across other ransomware brands, including Play, Medusa, RansomHub, Knight, ALPHV/BlackCat, and 8Base. Multiple researchers have noted overlaps suggesting a fluid affiliate or shared-backend ecosystem rather than rigidly isolated operations. BianLian has also been associated with use of tooling seen among rival gangs, including EDR-disruption utilities circulating in the ransomware affiliate landscape. Known aliases are limited in the provided reporting, and BianLian is most commonly referenced simply as BianLian. The group should not be confused with criminal scams that falsely impersonated the “BianLian Group” in mailed extortion letters; U.S. authorities assessed those letters as unrelated to the actual ransomware and data-extortion operation. By 2025, some reporting described BianLian as dormant, fragmented, or reduced in visibility compared with earlier activity, amid broader ransomware ecosystem churn and affiliate migration. Even so, the brand remains significant in threat intelligence because of its role in the rise of encryption-less extortion, its exploitation of enterprise software vulnerabilities, and its apparent connections to other major ransomware actors in the shared cybercriminal ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
CVE-2025-31324 (CVSS 10.0): A missing authorization check in the Visual Composer Metadata Uploader was actively exploited as a zero day by multiple threat actor groups, including Russian ransomware operators (BianLian, RansomEXX/Storm-2460), the Qilin ransomware as a service operation, and the China nexus APT group Earth Lamia.
The BianLian ransomware group was observed by GuidePoint Security exploiting CVE-2024-27198 and CVE-2024-27199 to deliver malware including Jasmin ransomware. CISA added CVE-2024-27198 to its Known Exploited Vulnerabilities catalog on March 7, 2024.
The BianLian ransomware group was observed by GuidePoint Security exploiting CVE-2024-27198 and CVE-2024-27199 to deliver malware including Jasmin ransomware.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another ransomware operation sharing malware-hash overlap with infrastructure associated with 8Base, indicating possible common tooling or shared backend ecosystem.
Mentioned as one of several threat actors that previously exploited SAP NetWeaver CVE-2025-31324 as a zero day.
Referenced as historical context for prior exploitation of JetBrains TeamCity vulnerabilities to deliver ransomware.
Frequently exploits RDP access and can use the default Windows RDP bitmap cache as a reconnaissance source during intrusions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.