Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors bianlian

Description

BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog. Known victims: 552 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

BianLian is a medium-sophistication ransomware group operating since July 2022 with a primary focus on financial gain through multi-pronged extortion tactics. The group uses a TOR-based blog to post victim data and demands, including the unique inclusion of an I2P mirror for their site. BianLian has targeted at least 552 victims across various industries, employing advanced techniques and tools to execute their ransomware campaigns.

Goals & Targeting

BianLian's primary objective is to maximize financial gain through ransomware campaigns and data extortion. While specific targeting by sector or country is not explicitly noted, their broad victim count (over 552) suggests they focus on sectors where victims have higher incentives to pay ransoms quickly, such as healthcare, education, and small-to-medium enterprises (SMEs). The group's multi-pronged extortion approach indicates a strategic focus on extracting maximum value from each compromise.

Enhanced Description

BianLian operates as a criminal ransomware group that leverages sophisticated tactics to encrypt victim systems and demand ransoms for decryption keys while threatening to release stolen data. Unique to BianLian at the time of their emergence was the use of an I2P mirror for their public blog, which they employ to shame victims and create pressure to pay the demanded ransoms. The group's operational approach involves both ransomware deployment and data exfiltration, combining these methods to maximize coercive leverage over their targets. BianLian has demonstrated a clear focus on financial gain through their extortion activities and has been active since July 2022 through March 2025, with no indication of slowing down.

Key Capabilities

  • Ransomware deployment with encryption
  • Data exfiltration with public shaming
  • Use of advanced persistence techniques
  • Multi-channel communication (TOR, I2P)
  • Sophisticated extortion tactics

MITRE ATT&CK Tactics

Credential Access
Defense-Evasion
Discovery
Execution
Exfiltration
Impact

ATT&CK Techniques

T1059.003
T1078
T1064
T1566.001
T1562

Software / Tooling

Custom ransomware
Phishing tools

Campaigns & Victims

BianLian's campaigns involve targeted deployment of ransomware followed by rapid data exfiltration and public shaming via their TOR blog. The group has demonstrated a preference for smaller to medium-sized enterprises and industries with less mature cybersecurity practices. Notable patterns include the use of multiple extortion tactics (ransomware and stolen data release threats) and persistence in victim targeting across geographic regions.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • TOR-based communication channels
  • IP addresses associated with C2 servers (e.g., 88.212.241.105, 91.245.255.27)
  • MD5 hashes of ransomware binaries and related tools

Recommended Actions

  • Implement robust endpoint detection and response solutions
  • Harden RDP access controls to prevent brute-force attacks
  • Monitor for unusual network activity, including TOR traffic
  • Conduct regular backups of critical systems, stored offline
  • Educate employees on phishing prevention techniques

Suggested Tags

Ransomware
Financial-Crime
Extortion
TOR
I2P

Confidence Assessment

The data on BianLian is moderately reliable with confirmed victims, hashes, and IPs linked to their activity. However, gaps exist in understanding the group's internal structure, long-term goals beyond financial gain, and specific targeting criteria across sectors and regions.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

214

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Data Exfiltration
Financial-Crime
Extortion
TOR
I2P

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jul 14, 2022
Last Seen
Mar 31, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.