BianLian, also known as the BianLian ransomware group or BianLian gang, is a financially motivated cybercriminal organization that develops malware and conducts ransomware and data-extortion operations. It is assessed to be based in Russia and has multiple Russia-based affiliates. The group has attacked organizations since at least June 2022, predominantly in the United States, with additional targeting in Australia, the United Kingdom, Canada, Europe, and Asia. Its victims span healthcare, financial services, government, manufacturing, professional and legal services, telecommunications, travel, construction, and property development. The group is distinct from the unrelated Android banking malware also called BianLian. BianLian initially employed double extortion, encrypting systems after stealing data and threatening public disclosure. Following the release of Avast's free decryptor in January 2023, it shifted primarily to data-theft extortion, adopting exclusively exfiltration-based extortion around January 2024. It operates a dedicated leak site and pressures victims through threats of reputational, legal, and financial harm, threatening telephone calls to employees, and ransom messages printed on compromised-network printers. Initial access methods include compromised RDP credentials, phishing, and exploitation of internet-facing applications. BianLian has exploited the Microsoft Exchange ProxyShell vulnerability chain and vulnerable TeamCity deployments. Its intrusion toolkit includes victim-specific Go backdoors, an obfuscated PowerShell backdoor, webshells, and legitimate remote-access software. The group relies heavily on native Windows utilities and PowerShell for discovery, credential theft, account manipulation, and lateral movement. It harvests credentials from memory, files, and Active Directory, exploits vulnerabilities for privilege escalation, and uses RDP, PsExec, WMI, and WinRM to expand access. Persistence mechanisms include newly created accounts, scheduled tasks, remote-management tools, and redundant backdoors. Defense evasion includes disabling endpoint protections, modifying firewall and security settings, disguising binaries and scheduled tasks, and vulnerable-driver abuse through EDRKillShifter. BianLian collects and stages sensitive information before exfiltrating it through FTP, Rclone, Mega, and other transfer utilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
However, prior flaws (CVE-2025-31324) impacting SAP products, including NetWeaver, have been weaponized by China-nexus espionage clusters like UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups such as BianLian and RansomExx. In April 2025, unknown threat actors were also observed exploiting the same critical SAP NetWeaver vulnerability to deploy a backdoor called Auto-Color.
The BianLian group has successfully targeted the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to gain initial access into victim networks.
The BianLian group has successfully targeted the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to gain initial access into victim networks.
The BianLian group has successfully targeted the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to gain initial access into victim networks.
The intrusion started with the exploitation of known TeamCity vulnerabilities CVE-2024-27198 and CVE-2023-42793, allowing the threat actor to infiltrate the victim’s system.
3 more CVEs tied to this actor tracked in Mallory.
140 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-based extortion group that shifted from ransomware encryption to pure data theft and coercive extortion after a decryptor became available.
Named because Qilin uses infrastructure that overlaps with BianLian; the reference provides no further details on BianLian activity.
Referenced as a cybercriminal group previously observed exploiting SAP product vulnerabilities, specifically CVE-2025-31324.
Referenced as a cybercrime group that previously weaponized SAP product flaws including CVE-2025-31324.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.