BI

Bianlian Ransomware

Tracked

Threat actor group tracked in the global ransomware database · Last disclosure: Mar 31, 2025

Ransomware-as-a-Service (RaaS) Double Extortion Target: Business Services
201
Total Victims
0.9% of all tracked
16
Countries Targeted
13
Sectors Targeted
2024
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Bianlian and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Bianlian, a ransomware operation identified in late 2021, has hit more than twenty victims across sixteen countries, focusing heavily on the United States, Canada, and India with sectors such as business services, healthcare, and financial services suffering most.

Who Bianlian is

BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog.

Recorded activity

Disclosures attributed to Bianlian in this database run from January 2024 to March 2025, totalling 201 victims — 0.9% of everything tracked here. Bianlian has listed victims in 16 countries in this database, most often United States, followed by Canada and India. The sectors appearing most in its listings are Business Services, Healthcare, Financial Services.

How Bianlian is documented to operate

Command and Scripting Interpreter T1059 Execution

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.

Mitigations: Restrict Web-Based Content, Limit Software Installation, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, Privileged Account Management

MITRE ATT&CK reference →
User Execution T1204 Execution

An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing. While User Execution frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing.

Mitigations: Network Intrusion Prevention, Restrict Web-Based Content, Limit Software Installation, User Training, Execution Prevention, Behavior Prevention on Endpoint

MITRE ATT&CK reference →
Software Packing T1027.002 Stealth

Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code. Utilities used to perform software packing are called packers. Example packers are MPRESS and UPX.

Mitigations: Antivirus/Antimalware

MITRE ATT&CK reference →
Masquerading T1036 Stealth

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.

Mitigations: User Training, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, User Account Management, Restrict File and Directory Permissions

MITRE ATT&CK reference →
Virtualization/Sandbox Evasion T1497 Stealth Discovery

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

MITRE ATT&CK reference →
System Information Discovery T1082 Discovery

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes. Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the <codesystemsetup</code configuration tool on macOS.

MITRE ATT&CK reference →
File and Directory Discovery T1083 Discovery

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Many command shell utilities can be used to obtain this information. Examples include <codedir</code, <codetree</code, <codels</code, <codefind</code, and <codelocate</code. Custom tools may also be used to gather file and directory information and interact with the Native API.

MITRE ATT&CK reference →
Peripheral Device Discovery T1120 Discovery

Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system. Peripheral devices could include auxiliary resources that support a variety of functionalities such as keyboards, printers, cameras, smart card readers, or removable storage. The information may be used to enhance their awareness of the system and network environment or may be used for further actions.

MITRE ATT&CK reference →
Security Software Discovery T1518.001 Discovery

Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

MITRE ATT&CK reference →
Replication Through Removable Media T1091 Lateral Movement Initial Access

Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself.

Mitigations: Limit Hardware Installation, Behavior Prevention on Endpoint, Disable or Remove Feature or Program

MITRE ATT&CK reference →

MITRE ATT&CK techniques attributed to Bianlian across its recorded activity. They describe the group overall, not any single incident.

Tooling observed in Bianlian operations

  • RDP Recognizer
  • Advanced IP Scanner
  • Advanced Port Scanner
  • PingCastle
  • SharpShares
  • SoftPerfect NetScan
  • WKTools
  • MEGA
  • RClone
  • PsExec
  • Impacket
  • AmmyyAdmin

Software reported in use by Bianlian. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.

Indicators of compromise

  • 36171704cde087f839b10c2465d864e1
  • d10e0387e3d55dc1f82c23719e2b168b
  • 0c756fc8f34e409650cd910b5e2a3f00
  • b3cdf0489ff37fe65141be9363b9489c
  • 08e76dd242e64bb31aec09db8464b28f
  • 14da9c0c4e3ac3b9abb2c48b37bece19
  • 104.238.35.179:38901
  • 151.236.16.242:12818
  • 85.235.151.5:8080
  • 5.255.106.12:80
  • 23.227.198.237:13937
  • 5.255.106.12:3389
  • [email protected]

Showing a sample of 8 MD5, 60 IP, 1 EMAIL on file. Hashes and network indicators published for Bianlian. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.

YARA detection rules

bianlian.yar
rule BianLian_Go_Ransomware {
	meta:
		description = "Detects BianLian ransomware"
		author = "BlackBerry Threat Research Team"
		date = "2022-09-13"
		license = "This Yara rule is provided under the Apache License 2.0 (https://www.apache.org/licenses/LICENSE-2.0) and open to any user or organization, as long as you use it under this license and ensure originator credit in any derivative to the BlackBerry Research & Intelligence Team"
	strings:
		$s1 = "trimpath=/home/jack/Projects/project1/"
		$s2 = "common.BuildPath"
		$s3 = "common.GetBlocksAmount"
		$s4 = "common.GetDrives"
		$s5 = "common.GetBlockSize"
		$s6 = "common.FileRename"
		$s7 = "common.GetFileExtension"
		$s8 = "exec.(*Cmd).Start.func1"
		$s9 = "exec.(*Cmd).Start.func2"
		$s10 = "exec.(*Cmd).Start.func3"
		$s11 = "CryptBlocks"
	condition:
		uint16(0) == 0x5a4d and all of them
}

Community-contributed rules for Bianlian, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat Actor Analysis

Bianlian is a ransomware threat group that has disclosed 201 victims in publicly accessible leak site data, representing 0.9% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Bianlian in our dataset dates to January 2024.

Geographically, Bianlian has targeted organisations in 16 countries. The most frequently targeted nation is United States with 163 victim organisations. Other heavily targeted nations include Canada, India, United Kingdom.

Industry-wise, Bianlian shows a concentration in the Business Services, Healthcare, Financial Services sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Bianlian likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 201 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 100 of 201)

# Organization Country Sector Date
1 CMC Technology Group cmctechgroup.com 🇻🇳 Vietnam Technology Mar 31, 2025
2 Meridian Senior meridiansenior.com 🇺🇸 United States Healthcare Mar 31, 2025
3 Saunders and Saunders sanders-sanders.co.uk 🇬🇧 United Kingdom Business Services Mar 31, 2025
4 Sonrisas Dental Health sonrisasdental.org 🇺🇸 United States Healthcare Mar 31, 2025
5 Goshen Medical Center goshenmedical.org 🇺🇸 United States Healthcare Mar 22, 2025
6 Allworx allworx.com 🇺🇸 United States Telecommunication Mar 7, 2025
7 Island Realty islandreality.com 🇺🇸 United States Business Services Mar 7, 2025
8 Minnesota Orthodontics minnesotaorthodontics.com 🇺🇸 United States Healthcare Mar 7, 2025
9 Ewald Consulting ewald-consulting.com 🇺🇸 United States Business Services Mar 4, 2025
10 Keystone Pacific Property Management LLC keystonepacificpm.com 🇺🇸 United States Business Services Mar 4, 2025
11 Legal Aid Society of Salt Lake legalaidsocietyofsaltlake.org 🇺🇸 United States Public Sector Mar 4, 2025
12 Mosley Glick O’Brien, Inc. mgoinc.com 🇺🇸 United States Financial Services Mar 4, 2025
13 Alabama Ophthalmology Associates aoapc.com 🇺🇸 United States Healthcare Feb 19, 2025
14 Aspire Rural Health System aspirerhs.org 🇺🇸 United States Healthcare Feb 13, 2025
15 Dain, Torpy, Le Ray, Wiest & Garner, P.C. daintorpy.com 🇺🇸 United States Business Services Feb 13, 2025
16 Financial Services of America, Inc. fsa1.com 🇺🇸 United States Financial Services Feb 13, 2025
17 Layfield & Borel CPA's L.L.C layfieldandborelcpas.com 🇺🇸 United States Financial Services Feb 13, 2025
18 Nash Brothers Construction 🇺🇸 United States Construction Feb 13, 2025
19 Nippon Steel USA nipponsteel.com 🇺🇸 United States Manufacturing Feb 13, 2025
20 D-7 Roofing d7roofing.com 🇺🇸 United States Construction Feb 10, 2025
21 Recievership Specialists recievershipspecialists.com 🇺🇸 United States Business Services Feb 10, 2025
22 Dash Business Business Services Feb 5, 2025
23 Hall Chadwick hallchadwick.com.au 🇦🇺 Australia Financial Services Feb 5, 2025
24 NESCTC Security Services nesctc.com 🇺🇸 United States Business Services Feb 5, 2025
25 C & R Molds Inc crmolds.com 🇺🇸 United States Manufacturing Feb 4, 2025
26 Commercial Solutions commercialsolutions.com 🇺🇸 United States Business Services Feb 4, 2025
27 Ayres Law Firm ayres-law-firm.com 🇺🇸 United States Business Services Feb 2, 2025
28 Civic Committee civiccommittee.org 🇺🇸 United States Public Sector Feb 2, 2025
29 Cyrious Software cyrious.com 🇺🇸 United States Technology Feb 2, 2025
30 Growth Acceleration Partners growthaccelerationpartners.com 🇺🇸 United States Technology Feb 2, 2025
31 Medical Associates of Brevard mabmd.com 🇺🇸 United States Healthcare Feb 2, 2025
32 MassDevelopment massdevelopment.com 🇺🇸 United States Public Sector Jan 18, 2025
33 Caframo Limited. caframo.com 🇨🇦 Canada Manufacturing Dec 26, 2024
34 Cottrell Fletcher & Cottrell P.C. cottrellaw.com 🇺🇸 United States Business Services Dec 18, 2024
35 Giordano, DelCollo, Werb & Gagne, LLC. gdwlawfirm.com 🇺🇸 United States Business Services Dec 18, 2024
36 American Computer Estimating Inc ace-it.com 🇺🇸 United States Technology Dec 14, 2024
37 MedRevenu Inc medrevenu.com 🇺🇸 United States Healthcare Dec 14, 2024
38 Mid Florida Primary Care mymfpc.com 🇺🇸 United States Healthcare Dec 14, 2024
39 Global Insurance Agency LLC iglobalinsure.com 🇺🇸 United States Financial Services Dec 10, 2024
40 Physicians' Primary Care of Southwest Florida ppcswfl.com 🇺🇸 United States Healthcare Dec 10, 2024
41 LTI Trucking Services ltitrucking.com 🇺🇸 United States Transportation/Logistics Dec 6, 2024
42 Star Shuttle Inc. starshuttle.com 🇺🇸 United States Transportation/Logistics Dec 5, 2024
43 Alpine Ear Nose & Throat alpineent.com 🇺🇸 United States Healthcare Dec 1, 2024
44 TWRU CPAs & Financial Advisors twru.com 🇺🇸 United States Financial Services Nov 26, 2024
45 Trinity Petroleum Management, LLC trinitymgt.com 🇺🇸 United States Energy Nov 22, 2024
46 Kellerhals Ferguson Kroblin PLLC kellfer.com 🇺🇸 United States Business Services Nov 21, 2024
47 Silverback Exploration silverbackexp.com 🇺🇸 United States Energy Nov 21, 2024
48 Amherstburg Family Health 🇨🇦 Canada Healthcare Nov 20, 2024
49 Immuno Laboratories, Inc immunolabs.com 🇺🇸 United States Healthcare Nov 10, 2024
50 ATSG, Inc atsg.net 🇺🇸 United States Transportation/Logistics Nov 9, 2024
51 Mizuno (USA) mizunousa.com 🇺🇸 United States Business Services Nov 9, 2024
52 Palmisano & Goodman, P.A. palmisanoandgoodman.com 🇺🇸 United States Business Services Nov 9, 2024
53 Healthcare Management Systems hcmsnapa.com 🇺🇸 United States Healthcare Nov 8, 2024
54 Falco Sult falcosult.com 🇮🇹 Italy Business Services Nov 5, 2024
55 L & B Transport, L.L.C. landbtransport.com 🇺🇸 United States Transportation/Logistics Nov 3, 2024
56 Russell Law Firm, LLC dannyrusselllaw.com 🇺🇸 United States Business Services Nov 3, 2024
57 CLAS Information Services clasinfo.com 🇺🇸 United States Business Services Oct 29, 2024
58 Premier Work Support premierworksupport.co.uk 🇬🇧 United Kingdom Business Services Oct 26, 2024
59 McElroy, Quirk & Burch, APC mqb-cpa 🇺🇸 United States Business Services Oct 24, 2024
60 Gluckstein Personal Injury Lawyers gluckstein.com 🇨🇦 Canada Business Services Oct 23, 2024
61 The Povman Law Firm povmanlaw.com 🇺🇸 United States Business Services Oct 23, 2024
62 Corporate Job Bank corporatejobbank.com 🇺🇸 United States Business Services Oct 16, 2024
63 Lein Law Offices leinlawoffices.com 🇺🇸 United States Business Services Oct 16, 2024
64 Boston Children's Health Physicians bostonchildrens.org 🇺🇸 United States Healthcare Oct 15, 2024
65 Pearl Cohen pearlcohen.com 🇺🇸 United States Business Services Oct 8, 2024
66 First Choice Sales & Marketing Group (First Choice) firstchoicesale.com 🇺🇸 United States Business Services Sep 24, 2024
67 River Region Cardiology Associates rrcamd.com 🇺🇸 United States Healthcare Sep 20, 2024
68 Hunter Dickinson Inc. 🇨🇦 Canada Energy Sep 19, 2024
69 Sherr Puttmann Akins Lamb PC spalfamilylaw.com 🇺🇸 United States Business Services Sep 17, 2024
70 Law Offices of Michael J Gurfinkel, Inc gurfinkel.com 🇺🇸 United States Business Services Sep 13, 2024
71 Ladov Law Firm ladovlaw.com 🇮🇱 Israel Business Services Sep 11, 2024
72 HDI hdimining.com 🇩🇪 Germany Manufacturing Sep 10, 2024
73 Anniversary Holding 🇨🇭 Switzerland Business Services Sep 9, 2024
74 Battle Lumber Co. battlelumber.com 🇺🇸 United States Agriculture and Food Production Sep 9, 2024
75 Smart Source, Inc. smartsource-inc.com 🇺🇸 United States Business Services Sep 9, 2024
76 CK Associates c-ka.com 🇺🇸 United States Business Services Sep 6, 2024
77 Keya Accounting and Tax Services LLC keyatax.com 🇺🇸 United States Business Services Sep 6, 2024
78 Western Supplies, Inc westernsupplies.com 🇺🇸 United States Business Services Sep 5, 2024
79 Eric Rossi CPA LLC ericrossicpa.com 🇺🇸 United States Financial Services Aug 30, 2024
80 ICWI 🇯🇲 Jamaica Financial Services Aug 30, 2024
81 Lane Supply Inc. lanesupplyinc.com 🇺🇸 United States Business Services Aug 30, 2024
82 Stein Fibers steinfibers.com 🇺🇸 United States Manufacturing Aug 30, 2024
83 Wayne Wright, LLP. waynewright.com 🇺🇸 United States Business Services Aug 30, 2024
84 Atwood & Cherny, P.C. 🇺🇸 United States Business Services Aug 28, 2024
85 Fish Nelson & Holden fishnelson.com 🇺🇸 United States Business Services Aug 28, 2024
86 M.Royo & KlockMetal mroyoklock 🇦🇷 Argentina Manufacturing Aug 28, 2024
87 Scott Pharma Solutions scottpharma.net 🇺🇸 United States Healthcare Aug 28, 2024
88 Sable International sableinternational.com 🇿🇦 South Africa Financial Services Aug 25, 2024
89 Studio Legale Associato Isolabella studioisolabella.com 🇮🇹 Italy Business Services Aug 24, 2024
90 Mohawk Valley Cardiology PC mohawkvalleycardiologypc.com 🇺🇸 United States Healthcare Aug 18, 2024
91 PBC Companies pbccompanies.com 🇺🇸 United States Construction Aug 18, 2024
92 Benson Kearley IFG - Insurance Brokers & Financial Advisors bkifg.com 🇨🇦 Canada Financial Services Aug 14, 2024
93 Texas Centers for Infectious Disease Associates texascentersid.com 🇺🇸 United States Healthcare Aug 14, 2024
94 Thompson Davis & Co thompsondavis.com 🇺🇸 United States Financial Services Aug 14, 2024
95 Southwest Family Medicine Associates sfmahealth.com 🇺🇸 United States Healthcare Aug 13, 2024
96 Anniversary Holding Company 🇺🇸 United States Business Services Aug 9, 2024
97 GCA Global Cargo Alliance gcargoglobal.com 🇺🇸 United States Transportation/Logistics Aug 9, 2024
98 Majestic Metals majesticmetalsinc.com 🇺🇸 United States Manufacturing Aug 9, 2024
99 Florence Cement Company, Inc. florencecement.com 🇺🇸 United States Business Services Jul 31, 2024
100 Sable International. sableinternational.com 🇬🇧 United Kingdom Financial Services Jul 31, 2024

Frequently Asked Questions

What is Bianlian ransomware?

Bianlian is a ransomware threat group that has claimed 201 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Bianlian attacked?

Bianlian has claimed 201 victims in our database, representing 0.9% of all tracked ransomware attacks. The most targeted countries are United States, Canada, India, United Kingdom.

Which countries does Bianlian target?

Bianlian has attacked organizations in 16 countries. The top targeted countries are: United States, Canada, India, United Kingdom.

Which industries does Bianlian target?

Bianlian most frequently targets the Business Services, Healthcare, Financial Services sectors based on victim disclosures in our database.

Is Bianlian still active?

Bianlian's most recent victim disclosure in our database was on March 31, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.