BianLian is a cybercriminal ransomware and extortion group active since late 2021 that evolved from conventional file-encrypting ransomware into primarily exfiltration-based data extortion by early 2023. The group is widely tracked as BianLian and has also been referred to as BianLian Group and BianLian ransomware group. It is distinct from unrelated Android malware that has sometimes been given the same name by some researchers. BianLian initially operated a double-extortion model, combining data theft with encryption and operating a leak site to pressure victims. Public reporting indicates the group later shifted away from routine encryption after January 2023 and focused on stealing data and threatening publication. The actor has been associated with leak-site operations, staged victim-name disclosure practices, and healthcare-focused extortion activity, with a notably high share of healthcare victims among major leak-site groups in 2023. The group has demonstrated strong intrusion tradecraft. Reported initial access methods include exploitation of Microsoft Exchange ProxyShell vulnerabilities, exploitation of SonicWall VPN devices, abuse of weak or exposed remote access credentials, exploitation of JetBrains TeamCity vulnerabilities CVE-2024-27198 and CVE-2024-27199, and exploitation of SAP vulnerabilities including CVE-2025-31324. BianLian has also been noted among ransomware actors that abuse legitimate remote monitoring and management tools. Post-compromise, BianLian relies heavily on living-off-the-land techniques and legitimate administrative mechanisms. Reported activity includes use of RDP, WinRM, WMI, and PowerShell for reconnaissance, lateral movement, and remote execution; account and permission manipulation; firewall and policy changes; and deployment of custom malware written in Go, including a backdoor and encryptor. The backdoor has been described as capable of retrieving payloads and executing them in memory. The group has shown deliberate efforts to minimize noisy reconnaissance and maintain persistence across compromised environments. BianLian is also known for aggressive defense evasion and post-exploitation behavior. Reported techniques include disabling or bypassing endpoint protections, interfering with Windows Defender and AMSI, modifying security product protections, deleting backups and shadow copies, and in at least one case using remote access tooling together with Safe Mode to reduce the effectiveness of security controls during encryption attempts. The actor has shown dwell times of weeks before monetization and has been assessed as technically capable in network compromise and lateral movement. Victimology spans multiple sectors, with repeated reporting on healthcare, manufacturing, and education, and broader activity against organizations in North America, the United Kingdom, and Australia. The group has also been linked to exploitation of enterprise software vulnerabilities shortly after disclosure, consistent with financially motivated opportunistic targeting. BianLian is best characterized as a financially motivated cybercrime actor specializing in ransomware-linked intrusion, data theft, and extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
However, prior flaws (CVE-2025-31324) impacting SAP products, including NetWeaver, have been weaponized by China-nexus espionage clusters like UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups such as BianLian and RansomExx. In April 2025, unknown threat actors were also observed exploiting the same critical SAP NetWeaver vulnerability to deploy a backdoor called Auto-Color.
The BianLian group has successfully targeted the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to gain initial access into victim networks.
The BianLian group has successfully targeted the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to gain initial access into victim networks.
The BianLian group has successfully targeted the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to gain initial access into victim networks.
The BianLian ransomware group was observed by GuidePoint Security exploiting CVE-2024-27198 and CVE-2024-27199 to deliver malware including Jasmin ransomware. CISA added CVE-2024-27198 to its Known Exploited Vulnerabilities catalog on March 7, 2024.
1 more CVE tied to this actor tracked in Mallory.
95 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a cybercriminal group previously observed exploiting SAP product vulnerabilities, specifically CVE-2025-31324.
Referenced as a cybercrime group that previously weaponized SAP product flaws including CVE-2025-31324.
Named as a threat actor receiving infrastructure support from Aeza Group.
Ransomware group whose infrastructure was hosted by Aeza Group.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.