Bianlian Ransomware
TrackedThreat actor group tracked in the global ransomware database · Last disclosure: Mar 31, 2025
ThreatAI Analysis
Compiled from the ransomware.live profile for Bianlian and from this database. Figures and technique mappings are quoted from the source data, not inferred.
Bianlian, a ransomware operation identified in late 2021, has hit more than twenty victims across sixteen countries, focusing heavily on the United States, Canada, and India with sectors such as business services, healthcare, and financial services suffering most.
Who Bianlian is
BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog.
Recorded activity
Disclosures attributed to Bianlian in this database run from January 2024 to March 2025, totalling 201 victims — 0.9% of everything tracked here. Bianlian has listed victims in 16 countries in this database, most often United States, followed by Canada and India. The sectors appearing most in its listings are Business Services, Healthcare, Financial Services.
How Bianlian is documented to operate
Command and Scripting Interpreter T1059 Execution
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.
Mitigations: Restrict Web-Based Content, Limit Software Installation, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, Privileged Account Management
MITRE ATT&CK reference →User Execution T1204 Execution
An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing. While User Execution frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing.
Mitigations: Network Intrusion Prevention, Restrict Web-Based Content, Limit Software Installation, User Training, Execution Prevention, Behavior Prevention on Endpoint
MITRE ATT&CK reference →Software Packing T1027.002 Stealth
Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code. Utilities used to perform software packing are called packers. Example packers are MPRESS and UPX.
Mitigations: Antivirus/Antimalware
MITRE ATT&CK reference →Masquerading T1036 Stealth
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.
Mitigations: User Training, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, User Account Management, Restrict File and Directory Permissions
MITRE ATT&CK reference →Virtualization/Sandbox Evasion T1497 Stealth Discovery
Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
MITRE ATT&CK reference →System Information Discovery T1082 Discovery
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes. Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the <codesystemsetup</code configuration tool on macOS.
MITRE ATT&CK reference →File and Directory Discovery T1083 Discovery
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Many command shell utilities can be used to obtain this information. Examples include <codedir</code, <codetree</code, <codels</code, <codefind</code, and <codelocate</code. Custom tools may also be used to gather file and directory information and interact with the Native API.
MITRE ATT&CK reference →Peripheral Device Discovery T1120 Discovery
Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system. Peripheral devices could include auxiliary resources that support a variety of functionalities such as keyboards, printers, cameras, smart card readers, or removable storage. The information may be used to enhance their awareness of the system and network environment or may be used for further actions.
MITRE ATT&CK reference →Security Software Discovery T1518.001 Discovery
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
MITRE ATT&CK reference →Replication Through Removable Media T1091 Lateral Movement Initial Access
Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself.
Mitigations: Limit Hardware Installation, Behavior Prevention on Endpoint, Disable or Remove Feature or Program
MITRE ATT&CK reference →MITRE ATT&CK techniques attributed to Bianlian across its recorded activity. They describe the group overall, not any single incident.
Tooling observed in Bianlian operations
- RDP Recognizer
- Advanced IP Scanner
- Advanced Port Scanner
- PingCastle
- SharpShares
- SoftPerfect NetScan
- WKTools
- MEGA
- RClone
- PsExec
- Impacket
- AmmyyAdmin
Software reported in use by Bianlian. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.
Indicators of compromise
- 36171704cde087f839b10c2465d864e1
- d10e0387e3d55dc1f82c23719e2b168b
- 0c756fc8f34e409650cd910b5e2a3f00
- b3cdf0489ff37fe65141be9363b9489c
- 08e76dd242e64bb31aec09db8464b28f
- 14da9c0c4e3ac3b9abb2c48b37bece19
- 104.238.35.179:38901
- 151.236.16.242:12818
- 85.235.151.5:8080
- 5.255.106.12:80
- 23.227.198.237:13937
- 5.255.106.12:3389
- [email protected]
Showing a sample of 8 MD5, 60 IP, 1 EMAIL on file. Hashes and network indicators published for Bianlian. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.
YARA detection rules
bianlian.yar
rule BianLian_Go_Ransomware {
meta:
description = "Detects BianLian ransomware"
author = "BlackBerry Threat Research Team"
date = "2022-09-13"
license = "This Yara rule is provided under the Apache License 2.0 (https://www.apache.org/licenses/LICENSE-2.0) and open to any user or organization, as long as you use it under this license and ensure originator credit in any derivative to the BlackBerry Research & Intelligence Team"
strings:
$s1 = "trimpath=/home/jack/Projects/project1/"
$s2 = "common.BuildPath"
$s3 = "common.GetBlocksAmount"
$s4 = "common.GetDrives"
$s5 = "common.GetBlockSize"
$s6 = "common.FileRename"
$s7 = "common.GetFileExtension"
$s8 = "exec.(*Cmd).Start.func1"
$s9 = "exec.(*Cmd).Start.func2"
$s10 = "exec.(*Cmd).Start.func3"
$s11 = "CryptBlocks"
condition:
uint16(0) == 0x5a4d and all of them
}
Community-contributed rules for Bianlian, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.
Threat Actor Analysis
Bianlian is a ransomware threat group that has disclosed 201 victims in publicly accessible leak site data, representing 0.9% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Bianlian in our dataset dates to January 2024.
Geographically, Bianlian has targeted organisations in 16 countries. The most frequently targeted nation is United States with 163 victim organisations. Other heavily targeted nations include Canada, India, United Kingdom.
Industry-wise, Bianlian shows a concentration in the Business Services, Healthcare, Financial Services sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Bianlian likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 201 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 100 of 201)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | CMC Technology Group cmctechgroup.com | 🇻🇳 Vietnam | Technology | Mar 31, 2025 |
| 2 | Meridian Senior meridiansenior.com | 🇺🇸 United States | Healthcare | Mar 31, 2025 |
| 3 | Saunders and Saunders sanders-sanders.co.uk | 🇬🇧 United Kingdom | Business Services | Mar 31, 2025 |
| 4 | Sonrisas Dental Health sonrisasdental.org | 🇺🇸 United States | Healthcare | Mar 31, 2025 |
| 5 | Goshen Medical Center goshenmedical.org | 🇺🇸 United States | Healthcare | Mar 22, 2025 |
| 6 | Allworx allworx.com | 🇺🇸 United States | Telecommunication | Mar 7, 2025 |
| 7 | Island Realty islandreality.com | 🇺🇸 United States | Business Services | Mar 7, 2025 |
| 8 | Minnesota Orthodontics minnesotaorthodontics.com | 🇺🇸 United States | Healthcare | Mar 7, 2025 |
| 9 | Ewald Consulting ewald-consulting.com | 🇺🇸 United States | Business Services | Mar 4, 2025 |
| 10 | Keystone Pacific Property Management LLC keystonepacificpm.com | 🇺🇸 United States | Business Services | Mar 4, 2025 |
| 11 | Legal Aid Society of Salt Lake legalaidsocietyofsaltlake.org | 🇺🇸 United States | Public Sector | Mar 4, 2025 |
| 12 | Mosley Glick O’Brien, Inc. mgoinc.com | 🇺🇸 United States | Financial Services | Mar 4, 2025 |
| 13 | Alabama Ophthalmology Associates aoapc.com | 🇺🇸 United States | Healthcare | Feb 19, 2025 |
| 14 | Aspire Rural Health System aspirerhs.org | 🇺🇸 United States | Healthcare | Feb 13, 2025 |
| 15 | Dain, Torpy, Le Ray, Wiest & Garner, P.C. daintorpy.com | 🇺🇸 United States | Business Services | Feb 13, 2025 |
| 16 | Financial Services of America, Inc. fsa1.com | 🇺🇸 United States | Financial Services | Feb 13, 2025 |
| 17 | Layfield & Borel CPA's L.L.C layfieldandborelcpas.com | 🇺🇸 United States | Financial Services | Feb 13, 2025 |
| 18 | Nash Brothers Construction | 🇺🇸 United States | Construction | Feb 13, 2025 |
| 19 | Nippon Steel USA nipponsteel.com | 🇺🇸 United States | Manufacturing | Feb 13, 2025 |
| 20 | D-7 Roofing d7roofing.com | 🇺🇸 United States | Construction | Feb 10, 2025 |
| 21 | Recievership Specialists recievershipspecialists.com | 🇺🇸 United States | Business Services | Feb 10, 2025 |
| 22 | Dash Business | — | Business Services | Feb 5, 2025 |
| 23 | Hall Chadwick hallchadwick.com.au | 🇦🇺 Australia | Financial Services | Feb 5, 2025 |
| 24 | NESCTC Security Services nesctc.com | 🇺🇸 United States | Business Services | Feb 5, 2025 |
| 25 | C & R Molds Inc crmolds.com | 🇺🇸 United States | Manufacturing | Feb 4, 2025 |
| 26 | Commercial Solutions commercialsolutions.com | 🇺🇸 United States | Business Services | Feb 4, 2025 |
| 27 | Ayres Law Firm ayres-law-firm.com | 🇺🇸 United States | Business Services | Feb 2, 2025 |
| 28 | Civic Committee civiccommittee.org | 🇺🇸 United States | Public Sector | Feb 2, 2025 |
| 29 | Cyrious Software cyrious.com | 🇺🇸 United States | Technology | Feb 2, 2025 |
| 30 | Growth Acceleration Partners growthaccelerationpartners.com | 🇺🇸 United States | Technology | Feb 2, 2025 |
| 31 | Medical Associates of Brevard mabmd.com | 🇺🇸 United States | Healthcare | Feb 2, 2025 |
| 32 | MassDevelopment massdevelopment.com | 🇺🇸 United States | Public Sector | Jan 18, 2025 |
| 33 | Caframo Limited. caframo.com | 🇨🇦 Canada | Manufacturing | Dec 26, 2024 |
| 34 | Cottrell Fletcher & Cottrell P.C. cottrellaw.com | 🇺🇸 United States | Business Services | Dec 18, 2024 |
| 35 | Giordano, DelCollo, Werb & Gagne, LLC. gdwlawfirm.com | 🇺🇸 United States | Business Services | Dec 18, 2024 |
| 36 | American Computer Estimating Inc ace-it.com | 🇺🇸 United States | Technology | Dec 14, 2024 |
| 37 | MedRevenu Inc medrevenu.com | 🇺🇸 United States | Healthcare | Dec 14, 2024 |
| 38 | Mid Florida Primary Care mymfpc.com | 🇺🇸 United States | Healthcare | Dec 14, 2024 |
| 39 | Global Insurance Agency LLC iglobalinsure.com | 🇺🇸 United States | Financial Services | Dec 10, 2024 |
| 40 | Physicians' Primary Care of Southwest Florida ppcswfl.com | 🇺🇸 United States | Healthcare | Dec 10, 2024 |
| 41 | LTI Trucking Services ltitrucking.com | 🇺🇸 United States | Transportation/Logistics | Dec 6, 2024 |
| 42 | Star Shuttle Inc. starshuttle.com | 🇺🇸 United States | Transportation/Logistics | Dec 5, 2024 |
| 43 | Alpine Ear Nose & Throat alpineent.com | 🇺🇸 United States | Healthcare | Dec 1, 2024 |
| 44 | TWRU CPAs & Financial Advisors twru.com | 🇺🇸 United States | Financial Services | Nov 26, 2024 |
| 45 | Trinity Petroleum Management, LLC trinitymgt.com | 🇺🇸 United States | Energy | Nov 22, 2024 |
| 46 | Kellerhals Ferguson Kroblin PLLC kellfer.com | 🇺🇸 United States | Business Services | Nov 21, 2024 |
| 47 | Silverback Exploration silverbackexp.com | 🇺🇸 United States | Energy | Nov 21, 2024 |
| 48 | Amherstburg Family Health | 🇨🇦 Canada | Healthcare | Nov 20, 2024 |
| 49 | Immuno Laboratories, Inc immunolabs.com | 🇺🇸 United States | Healthcare | Nov 10, 2024 |
| 50 | ATSG, Inc atsg.net | 🇺🇸 United States | Transportation/Logistics | Nov 9, 2024 |
| 51 | Mizuno (USA) mizunousa.com | 🇺🇸 United States | Business Services | Nov 9, 2024 |
| 52 | Palmisano & Goodman, P.A. palmisanoandgoodman.com | 🇺🇸 United States | Business Services | Nov 9, 2024 |
| 53 | Healthcare Management Systems hcmsnapa.com | 🇺🇸 United States | Healthcare | Nov 8, 2024 |
| 54 | Falco Sult falcosult.com | 🇮🇹 Italy | Business Services | Nov 5, 2024 |
| 55 | L & B Transport, L.L.C. landbtransport.com | 🇺🇸 United States | Transportation/Logistics | Nov 3, 2024 |
| 56 | Russell Law Firm, LLC dannyrusselllaw.com | 🇺🇸 United States | Business Services | Nov 3, 2024 |
| 57 | CLAS Information Services clasinfo.com | 🇺🇸 United States | Business Services | Oct 29, 2024 |
| 58 | Premier Work Support premierworksupport.co.uk | 🇬🇧 United Kingdom | Business Services | Oct 26, 2024 |
| 59 | McElroy, Quirk & Burch, APC mqb-cpa | 🇺🇸 United States | Business Services | Oct 24, 2024 |
| 60 | Gluckstein Personal Injury Lawyers gluckstein.com | 🇨🇦 Canada | Business Services | Oct 23, 2024 |
| 61 | The Povman Law Firm povmanlaw.com | 🇺🇸 United States | Business Services | Oct 23, 2024 |
| 62 | Corporate Job Bank corporatejobbank.com | 🇺🇸 United States | Business Services | Oct 16, 2024 |
| 63 | Lein Law Offices leinlawoffices.com | 🇺🇸 United States | Business Services | Oct 16, 2024 |
| 64 | Boston Children's Health Physicians bostonchildrens.org | 🇺🇸 United States | Healthcare | Oct 15, 2024 |
| 65 | Pearl Cohen pearlcohen.com | 🇺🇸 United States | Business Services | Oct 8, 2024 |
| 66 | First Choice Sales & Marketing Group (First Choice) firstchoicesale.com | 🇺🇸 United States | Business Services | Sep 24, 2024 |
| 67 | River Region Cardiology Associates rrcamd.com | 🇺🇸 United States | Healthcare | Sep 20, 2024 |
| 68 | Hunter Dickinson Inc. | 🇨🇦 Canada | Energy | Sep 19, 2024 |
| 69 | Sherr Puttmann Akins Lamb PC spalfamilylaw.com | 🇺🇸 United States | Business Services | Sep 17, 2024 |
| 70 | Law Offices of Michael J Gurfinkel, Inc gurfinkel.com | 🇺🇸 United States | Business Services | Sep 13, 2024 |
| 71 | Ladov Law Firm ladovlaw.com | 🇮🇱 Israel | Business Services | Sep 11, 2024 |
| 72 | HDI hdimining.com | 🇩🇪 Germany | Manufacturing | Sep 10, 2024 |
| 73 | Anniversary Holding | 🇨🇭 Switzerland | Business Services | Sep 9, 2024 |
| 74 | Battle Lumber Co. battlelumber.com | 🇺🇸 United States | Agriculture and Food Production | Sep 9, 2024 |
| 75 | Smart Source, Inc. smartsource-inc.com | 🇺🇸 United States | Business Services | Sep 9, 2024 |
| 76 | CK Associates c-ka.com | 🇺🇸 United States | Business Services | Sep 6, 2024 |
| 77 | Keya Accounting and Tax Services LLC keyatax.com | 🇺🇸 United States | Business Services | Sep 6, 2024 |
| 78 | Western Supplies, Inc westernsupplies.com | 🇺🇸 United States | Business Services | Sep 5, 2024 |
| 79 | Eric Rossi CPA LLC ericrossicpa.com | 🇺🇸 United States | Financial Services | Aug 30, 2024 |
| 80 | ICWI | 🇯🇲 Jamaica | Financial Services | Aug 30, 2024 |
| 81 | Lane Supply Inc. lanesupplyinc.com | 🇺🇸 United States | Business Services | Aug 30, 2024 |
| 82 | Stein Fibers steinfibers.com | 🇺🇸 United States | Manufacturing | Aug 30, 2024 |
| 83 | Wayne Wright, LLP. waynewright.com | 🇺🇸 United States | Business Services | Aug 30, 2024 |
| 84 | Atwood & Cherny, P.C. | 🇺🇸 United States | Business Services | Aug 28, 2024 |
| 85 | Fish Nelson & Holden fishnelson.com | 🇺🇸 United States | Business Services | Aug 28, 2024 |
| 86 | M.Royo & KlockMetal mroyoklock | 🇦🇷 Argentina | Manufacturing | Aug 28, 2024 |
| 87 | Scott Pharma Solutions scottpharma.net | 🇺🇸 United States | Healthcare | Aug 28, 2024 |
| 88 | Sable International sableinternational.com | 🇿🇦 South Africa | Financial Services | Aug 25, 2024 |
| 89 | Studio Legale Associato Isolabella studioisolabella.com | 🇮🇹 Italy | Business Services | Aug 24, 2024 |
| 90 | Mohawk Valley Cardiology PC mohawkvalleycardiologypc.com | 🇺🇸 United States | Healthcare | Aug 18, 2024 |
| 91 | PBC Companies pbccompanies.com | 🇺🇸 United States | Construction | Aug 18, 2024 |
| 92 | Benson Kearley IFG - Insurance Brokers & Financial Advisors bkifg.com | 🇨🇦 Canada | Financial Services | Aug 14, 2024 |
| 93 | Texas Centers for Infectious Disease Associates texascentersid.com | 🇺🇸 United States | Healthcare | Aug 14, 2024 |
| 94 | Thompson Davis & Co thompsondavis.com | 🇺🇸 United States | Financial Services | Aug 14, 2024 |
| 95 | Southwest Family Medicine Associates sfmahealth.com | 🇺🇸 United States | Healthcare | Aug 13, 2024 |
| 96 | Anniversary Holding Company | 🇺🇸 United States | Business Services | Aug 9, 2024 |
| 97 | GCA Global Cargo Alliance gcargoglobal.com | 🇺🇸 United States | Transportation/Logistics | Aug 9, 2024 |
| 98 | Majestic Metals majesticmetalsinc.com | 🇺🇸 United States | Manufacturing | Aug 9, 2024 |
| 99 | Florence Cement Company, Inc. florencecement.com | 🇺🇸 United States | Business Services | Jul 31, 2024 |
| 100 | Sable International. sableinternational.com | 🇬🇧 United Kingdom | Financial Services | Jul 31, 2024 |
Frequently Asked Questions
What is Bianlian ransomware?
Bianlian is a ransomware threat group that has claimed 201 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Bianlian attacked?
Bianlian has claimed 201 victims in our database, representing 0.9% of all tracked ransomware attacks. The most targeted countries are United States, Canada, India, United Kingdom.
Which countries does Bianlian target?
Bianlian has attacked organizations in 16 countries. The top targeted countries are: United States, Canada, India, United Kingdom.
Which industries does Bianlian target?
Bianlian most frequently targets the Business Services, Healthcare, Financial Services sectors based on victim disclosures in our database.
Is Bianlian still active?
Bianlian's most recent victim disclosure in our database was on March 31, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.