BianLian is a financially motivated ransomware and data-extortion operation, assessed by the FBI as likely Russia-based, active since at least 2022. It initially conducted double-extortion attacks using a custom Go-based encryptor and threatening publication of stolen data. After a public decryptor became available in January 2023, the operation shifted primarily to exfiltration-only extortion, retaining stolen data as leverage rather than encrypting victim systems. BianLian has targeted organizations globally, with substantial activity against U.S. organizations and notable targeting of healthcare, manufacturing, education, telecommunications, and other enterprises. Historical intrusions involved exploitation of ProxyShell vulnerabilities and SonicWall VPN appliances, abuse of compromised remote-access credentials, and use of external remote services. Operators have used RDP, WinRM, WMI, PowerShell, scheduled tasks, account manipulation, credential dumping, network and domain discovery, remote-access tooling, and cloud or alternative-protocol data transfer. They have also disabled or modified endpoint protections and firewalls, altered security settings, and deployed custom backdoors to preserve access. A distinct Android banking-malware family has also been called BianLian in some reporting, but it has no established operational connection to the BianLian ransomware operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The BianLian group has successfully targeted the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to gain initial access into victim networks. | The BianLian group has developed a custom tool set consisting of a backdoor and an encryptor, developing both using the Go programming language.
The BianLian group has successfully targeted the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to gain initial access into victim networks. | The BianLian group has developed a custom tool set consisting of a backdoor and an encryptor, developing both using the Go programming language.
The BianLian group has successfully targeted the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to gain initial access into victim networks. | The BianLian group has developed a custom tool set consisting of a backdoor and an encryptor, developing both using the Go programming language.
CVE-2024–27198: A vulnerability in JetBrains software leveraged by BianLian for data extortion operations. While not directly Qilin, it shows the types of software vulnerabilities targeted by sophisticated RaaS groups. | CVE-2024–27198: A vulnerability in JetBrains software leveraged by BianLian for data extortion operations.
SAP NetWeaver, a cornerstone for enterprise operations across countless global organizations, faces a severe threat from a newly discovered deserialization vulnerability, CVE-2025-42980. With a CVSS score of 9.1, this flaw could enable attackers to execute arbitrary code... Threat Intelligence Active exploitation by ransomware groups, including BianLian and Ransomexx, has been observed.
First observed in attacks in June 2022, BianLian was seen targeting critical infrastructure organizations and private entities in the US and abroad. The group has been stealing victim data, using it for extortion.
First observed in attacks in June 2022, BianLian was seen targeting critical infrastructure organizations and private entities in the US and abroad. The group has been stealing victim data, using it for extortion.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since June 2022, BianLian ... shifted tactics from data encryption to solely data exfiltration after Avast released a decryption tool in January 2023.
Since June 2022, BianLian ... shifted tactics from data encryption to solely data exfiltration after Avast released a decryption tool in January 2023.
The BianLian group has developed a custom tool set consisting of a backdoor and an encryptor, developing both using the Go programming language.
44 distinct techniques documented for this family, organized by ATT&CK tactic.
At a first look, it seemed clear that the APK was heavily obfuscated... It seems to mostly rely on generating a variety of random functions to hide the real functionalities of the sample... Most of the strings in the code are generated by using functions implementing a XOR decryption of byte arrays.
The BianLian sample installs fine on Android 8. The (fake) server BianLian communicates to a C&C via HTTP. | BianLian communicates to a C&C via HTTP.
This module is used to create a functioning SSH server on the device using JSCH... BianLian can setup a proxy that can run SSH sessions using remote port forwarding on port 34500, with an implementation similar to 2017’s malware MilkyDoor, making communication with the CC harder to detect.
167 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
79 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Likely Russia-based extortion operation that shifted from double-extortion ransomware to exclusively stealing data and threatening publication after a free decryptor became available.
Ransomware family mentioned as possibly linked to the crypting actor hiddenroot.
Ransomware family mentioned as one of the criminal services hosted by Aeza Group infrastructure.
Financially motivated ransomware group that opportunistically targets multiple sectors and publishes stolen data on the dark web.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.