BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog. Known victims: 552 1 ransom note(s) on file
Objectives
Executive Summary
BianLian is a medium-sophistication ransomware group operating since July 2022 with a primary focus on financial gain through multi-pronged extortion tactics. The group uses a TOR-based blog to post victim data and demands, including the unique inclusion of an I2P mirror for their site. BianLian has targeted at least 552 victims across various industries, employing advanced techniques and tools to execute their ransomware campaigns.
Goals & Targeting
BianLian's primary objective is to maximize financial gain through ransomware campaigns and data extortion. While specific targeting by sector or country is not explicitly noted, their broad victim count (over 552) suggests they focus on sectors where victims have higher incentives to pay ransoms quickly, such as healthcare, education, and small-to-medium enterprises (SMEs). The group's multi-pronged extortion approach indicates a strategic focus on extracting maximum value from each compromise.
Enhanced Description
BianLian operates as a criminal ransomware group that leverages sophisticated tactics to encrypt victim systems and demand ransoms for decryption keys while threatening to release stolen data. Unique to BianLian at the time of their emergence was the use of an I2P mirror for their public blog, which they employ to shame victims and create pressure to pay the demanded ransoms. The group's operational approach involves both ransomware deployment and data exfiltration, combining these methods to maximize coercive leverage over their targets. BianLian has demonstrated a clear focus on financial gain through their extortion activities and has been active since July 2022 through March 2025, with no indication of slowing down.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BianLian's campaigns involve targeted deployment of ransomware followed by rapid data exfiltration and public shaming via their TOR blog. The group has demonstrated a preference for smaller to medium-sized enterprises and industries with less mature cybersecurity practices. Notable patterns include the use of multiple extortion tactics (ransomware and stolen data release threats) and persistence in victim targeting across geographic regions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data on BianLian is moderately reliable with confirmed victims, hashes, and IPs linked to their activity. However, gaps exist in understanding the group's internal structure, long-term goals beyond financial gain, and specific targeting criteria across sectors and regions.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
214
IOCs
0
Observed Data
0
Tactics