Home/Threat Actor/BianLian
Threat Actor

BianLian

bianlian · russia_speaking_cybercrime · active since 2022-06

BianLian (canonical CISA + FBI + ASD-ACSC naming per May 16, 2023 #StopRansomware joint advisory AA23-136A, updated November 20, 2024 with additional TTPs obtained as of June 2024 through FBI + ASD's ACSC investigations + industry threat intelligence) is a Russia-based ransomware developer + deployer + data extortion cybercriminal group with multiple Russia-based affiliates ("likely based in Russia, with multiple Russia-based affiliates" per CISA), active since June 2022 targeting U.S. + Australian critical infrastructure.

Russia-based organized cybercrime attribution via CISA + FBI + ASD-ACSC canonical joint advisory + CrowdStrike + Microsoft + Sophos contributing parties + CISA November 2024 cluster-defining foreign-language-name-misattribution signature ("The reporting agencies are aware of multiple ransomware groups, like BianLian, that seek to misattribute location and nationality by choosing foreign-language names, almost certainly to complicate attribution efforts")

standalone cluster paralleling inc_ransom + base_8 + noescape in v0.1.148 post-Conti-takedown 2022-2024 RaaS fragmentation operators cell.

operational target profile U.S. critical infrastructure sectors primary target per FBI June 2022 onward + Australian critical infrastructure + private enterprises + professional services + property development per ACSC + 154+ victims listed on extortion portal 2024 per Bleeping Computer with notable victims Air Canada + Northern Minerals + Boston Children's Health Physicians + global Japanese sportswear manufacturer + Texas clinic + global mining group + international financial advisory + major U.S. dermatology practice.

operational attack architecture: (1) cluster-defining valid RDP credentials initial access "possibly purchased from initial access brokers or acquired through phishing" per CISA.

(2) cluster-defining custom Go-based backdoor signature implant per CISA + Bleeping Computer.

(3) PowerShell + Windows Command Shell native tools for discovery + credential harvesting + AV disabling per CISA.

(4) Windows Defender + Sophos SAVEnabled tamper protection bypass via Registry modifications + Windows firewall rule modification for RDP access + Remote Desktop Users group account addition per CISA.

(5) cluster-defining Rclone + FTP + Mega exfiltration tradecraft with Rclone installed in generic typically-unchecked folders (programdata/vmware + music folders per FBI)

(6) cluster-defining November 2024 update TTPs: Windows + ESXi infrastructure targeting + possible ProxyShell exploit chain (CVE-2021-34473 + CVE-2021-34523 + CVE-2021-31207) + Ngrok + modified Rsocks SOCKS5 tunnel destination masking.

(7) cluster-defining extortion-model pivot from double-extortion to exclusively-exfiltration January 2023 - January 2024 per CISA following Avast decryptor January 2023 defeat of encryption capability ("BianLian group originally employed a double-extortion model in which they encrypted victims' systems after exfiltrating the data; however, they shifted primarily to exfiltration-based extortion around January 2023 and shifted to exclusively exfiltration-based extortion around January 2024")

(8) cluster-defining foreign- language-name-misattribution tradecraft per CISA November 2024, Mandarin-like name chosen to complicate attribution.

cluster fills the Russia- based-2022-onward + Go-based-backdoor + extortion- model-pivot-January-2024 + foreign-language-name- misattribution position in post-Conti-takedown 2022-2024 RaaS fragmentation operators cell; canonical illustration of double-extortion - exclusively-exfiltration ransomware operational pivot + Russia-based cybercrime + foreign-language- misattribution tradecraft + custom Go-based backdoor + Rclone/FTP/Mega exfiltration + ProxyShell + Ngrok- Rsocks-SOCKS5 traffic masking cited in essentially all subsequent post-Conti-takedown ransomware industry analyses through 2022-2026 period.

russia_speaking_cybercrime confidence: high 11 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited4

Profile

BianLian (canonical CISA + FBI + ASD-ACSC naming per May 16, 2023 #StopRansomware joint advisory AA23-136A, updated November 20, 2024) is a Russia- based ransomware developer + deployer + data extortion cybercriminal group with multiple Russia- based affiliates, active since June 2022 targeting U.S. + Australian critical infrastructure. Russia-based organized cybercrime attribution via CISA + FBI + ASD-ACSC canonical joint advisory + CISA November 2024 foreign-language-name-misattribution signature identification. Standalone cluster paralleling inc_ransom + base_8 + noescape in v0.1.148 post-Conti-takedown 2022-2024 RaaS fragmentation operators cell.

Operational target profile
  • U.S. critical infrastructure sectors primary target per FBI June 2022 onward.
  • Australian critical infrastructure + private enterprises + professional services + property development per ACSC.
  • 154+ victims listed on extortion portal 2024 per Bleeping Computer.
  • Notable victims: Air Canada + Northern Minerals + Boston Children's Health Physicians Operational attack architecture: (1) Valid RDP credentials initial access (cluster- defining): possibly purchased from initial access brokers or acquired through phishing per CISA (2) Custom Go-based backdoor (cluster-defining): signature implant per CISA + Bleeping Computer (3) PowerShell + Windows Command Shell native tools (signature): for discovery + credential harvesting + AV disabling per CISA (4) Disable Windows Defender + Sophos SAVEnabled (signature): tamper protection bypass via Registry modifications (5) Rclone + FTP + Mega exfiltration (cluster- defining): signature data theft tradecraft (6) November 2024 update TTPs (cluster-defining):.
  • Windows + ESXi infrastructure targeting.
  • Possible ProxyShell exploit chain (CVE-2021-34473 + CVE-2021-34523 + CVE-2021-31207)
  • Ngrok + modified Rsocks SOCKS5 tunnel masking (7) Extortion-model pivot January 2023.
  • January 2024 (cluster-defining): per CISA, originally double-extortion (encrypt + leak), shifted to exclusively exfiltration-based extortion by January 2024 after Avast decryptor January 2023 defeat of encryption capability (8) Foreign-language name misattribution (signature): per CISA November 2024, Mandarin-like name chosen "almost certainly to complicate attribution efforts" The cluster fills the Russia-based-2022-onward + Go-based-backdoor + extortion-model-pivot-January- 2024 position in the post-Conti-takedown 2022-2024 RaaS fragmentation operators cell.

Aliases

11
bianlianbian lianbianlian_groupbianlian_ransomwarebianlian_data_extortion_groupbianlian ransomware groupbianlian russia-based ransomware data extortion cybercriminalbianlian fbi cisa asd acsc stopransomware advisorybianlian shifted to exfiltration based extortion january 2024bianlian go-based custom backdoorbianlian foreign language name misattribution

Notable Campaigns

7
2024CISA Canonical November 20, 2024 Advisory Update
2024BianLian 2024 Prolific Year, 154+ Victims
2023-2024BianLian Extortion-Model Pivot, Double to Exclusively Exfiltration-Based (January 2023 - January 2024)
2023Avast Decryptor Release + Encryption Capability Defeat (January 2023)
2023CISA + FBI + ASD-ACSC Canonical #StopRansomware Advisory (May 16, 2023)
2022-2026Continued Industry Reference Status (2022-2026)
2022BianLian Origin, Active Since June 2022

Attribution & Reporting

Attributed by
CISA / FBI / ASD-ACSC (canonicalCrowdStrike (canonical contributor to CISA advisory)Microsoft (canonical contributor to CISA advisory)Sophos (canonical contributor to CISA advisory)Bleeping Computer (canonical 2023-2024 BianLian operational + advisory coverage)Decipher / Duo Security (canonical 2023 BianLian extortion-model-shift coverage)Heimdal Security (canonical November 2024 BianLian update coverage)CPO Magazine (canonical 2023 BianLian extortion shift coverage)AttackIQ (canonical attack graph response to BianLian advisory)Halcyon Jon Miller (canonical industry CEO/analyst commentary)Exabeam Randeep Gill (canonical industry EDR exploitation commentary)Redacted (canonical industry intel on BianLian victim-tailored messaging)
Key reporting
reportCISA + FBI + ASD-ACSC: #StopRansomware, BianLian Ransomware Group AA23-136A (May 16, 2023 + November 20, 2024 update), canonical joint advisory
reportFBI IC3: BianLian Ransomware Group Cybersecurity Advisory CSA (May 16, 2023), canonical FBI PDF
reportBleeping Computer: FBI confirms BianLian ransomware switch to extortion-only attacks (May 19, 2023), canonical extortion-shift coverage
reportBleeping Computer: CISA says BianLian ransomware now focuses only on data theft (November 2024), canonical November update coverage
reportDecipher / Duo Security: CISA Warns BianLian Ransomware Group Has Moved to Extortion Model (May 2023)
reportHeimdal Security: CISA, BianLian Ransomware Focus Switches to Data Theft (November 2024)
reportCPO Magazine: BianLian Ransomware Gang Shifts to Purely Data Extortion Attacks (May 2023)
reportAttackIQ: Attack Graph Response to CISA Advisory (AA23-136A), StopRansomware BianLian Ransomware Group
reportCrowdStrike: canonical contributor to CISA advisory
reportMicrosoft: canonical contributor to CISA advisory
reportSophos: canonical contributor to CISA advisory

Operational

State sponsor

Russia-based organized cybercrime, CISA + FBI + ASD-ACSC canonical attribution. Operationally separate from state-sponsored APT activity. Attribution chain: (1) CISA + FBI + ASD-ACSC canonical #StopRansomware joint advisory May 16, 2023 (updated November 20, 2024): per CISA "BianLian Ransomware Group" joint advisory AA23-136A: "BianLian is a ransomware developer, deployer, and data extortion cybercriminal group, likely based in Russia, with multiple Russia- based affiliates." CrowdStrike + Microsoft + Sophos contributed. (2) CISA November 20, 2024 update with Russia-based attribution + foreign-language name misattribution signature: per CISA November 2024 advisory update: "The reporting agencies are aware of multiple ransomware groups, like BianLian, that seek to misattribute location and nationality by choosing foreign-language names, almost certainly to complicate attribution efforts." (3) CISA + FBI canonical operational tracking June 2022 onward: per CISA: "Since June 2022, FBI has observed BianLian group affecting organizations in multiple U.S. critical infrastructure sectors. In Australia, ASD's ACSC has observed BianLian group predominately targeting private enterprises, including one critical infrastructure organization." (4) Avast decryptor January 2023 + extortion-model shift signature: per Bleeping Computer + Decipher: "After Avast published a decryptor for the family in January 2023, BianLian had begun to gradually abandon file encryption techniques in favor of data theft extortion." Operationally significant cluster-defining shift from double-extortion to exclusively exfiltration-based extortion January 2024 per CISA November 2024 update. (5) November 2024 advisory update operational details: per CISA: BianLian "targets Windows and ESXi infrastructure, possibly the ProxyShell exploit chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) for initial access. Uses Ngrok and modified Rsocks to mask traffic destinations using SOCK5 tunnels." Operational mission objective: Data theft extortion via custom Go-based backdoor + valid RDP credentials initial access + Rclone/FTP/Mega exfiltration + extortion threatening data release. Originally double-extortion encrypt-and-leak.

now exclusively exfiltration-based extortion since January 2024.

Operational target profile
  • U.S. critical infrastructure primary target per CISA June 2022 onward tracking.
  • Australian critical infrastructure + private enterprises + professional services + property development per ACSC tracking.
  • 154+ victims listed on extortion portal 2024 per Bleeping Computer.
  • Notable high-profile victims: Air Canada, Northern Minerals, Boston Children's Health Physicians, global Japanese sportswear manufacturer, Texas clinic, global mining group, international financial advisory, major U.S. dermatology practice per Bleeping Computer November 2024 The cluster fills the Russia-based-2022-onward + Go-based-backdoor + extortion-model-pivot-January- 2024 position in the post-Conti-takedown 2022-2024 RaaS fragmentation operators cell.
Motivations
financial_extortion_data_theft_double_extortion_pivoted_to_exclusively_exfiltration_january_2024, u_s_critical_infrastructure_targeting, australian_critical_infrastructure_targeting, russia_based_organized_cybercrime_operations, foreign_language_name_misattribution_tradecraft, go_based_custom_backdoor_signature_capability, rclone_ftp_mega_exfiltration_signature_tradecraft
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)36/60 · 60%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEGA CLOUD STORAGEMODIFIED RSOCKS SOCKS5 TUNNEL MASKINGSOFTPERFECT NETWORK SCANNER
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin