BianLian is a Go-based ransomware family associated with the financially motivated BianLian cybercriminal group, which has attacked organizations across multiple sectors since at least June 2022. Its operators originally used double extortion, stealing sensitive information before encrypting files and demanding payment. Following the release of an Avast decryptor in January 2023, the group shifted primarily toward data-theft extortion and, around January 2024, moved exclusively to extortion without encryption. Targets include healthcare, manufacturing, education, financial services, professional services, and other critical infrastructure organizations, particularly in the United States and Australia.
The group's custom Go toolset includes an encryptor and victim-specific backdoors. The encryptor makes files inaccessible and creates ransom notes. The backdoor retrieves arbitrary payloads from command-and-control infrastructure and executes them in memory, supporting continued access and post-exploitation. A PowerShell implementation has also been deployed after security software blocked the standard Go backdoor. This alternative uses layered obfuscation, certificate-validated SSL communications, and .NET runspace pools for asynchronous remote command execution.
BianLian intrusions use compromised RDP credentials, phishing, and exploitation of exposed applications. Observed operations include exploitation of the Microsoft Exchange ProxyShell vulnerability chain and compromise of vulnerable JetBrains TeamCity servers. Operators use native Windows utilities and third-party tools for discovery, credential dumping, privilege escalation, lateral movement, and persistence. They disable security protections, manipulate accounts and remote-access settings, and install legitimate remote-management software. Stolen data is transferred using tools and services including FTP, Rclone, and Mega. Extortion pressure includes threats to publish sensitive information, leak-site announcements, and threatening calls to victim employees.
BianLian is also the name of a separate Android banking trojan first discussed in 2018. No connection between that Android malware and the ransomware operation has been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-27198 is a critical authentication bypass vulnerability identified within the web component of JetBrains TeamCity versions before 2023.11.4. This vulnerability enables remote unauthenticated attackers to circumvent authentication checks by crafting specific URLs. | Actors associated with the BianLian and Jasmin ransomware families have utilized this vulnerability.
After multiple failed attempts to execute their standard GO backdoor, the threat actor pivoted to living off the land and leveraged a PowerShell implementation of their backdoor, which provides an almost identical functionality to what they would have with their GO backdoor.
The BianLian group has successfully targeted the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to gain initial access into victim networks. | The BianLian group has developed a custom tool set consisting of a backdoor and an encryptor, developing both using the Go programming language.
The BianLian group has successfully targeted the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to gain initial access into victim networks. | The BianLian group has developed a custom tool set consisting of a backdoor and an encryptor, developing both using the Go programming language.
The BianLian group has successfully targeted the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to gain initial access into victim networks. | The BianLian group has developed a custom tool set consisting of a backdoor and an encryptor, developing both using the Go programming language.
SAP NetWeaver, a cornerstone for enterprise operations across countless global organizations, faces a severe threat from a newly discovered deserialization vulnerability, CVE-2025-42980. With a CVSS score of 9.1, this flaw could enable attackers to execute arbitrary code... Threat Intelligence Active exploitation by ransomware groups, including BianLian and Ransomexx, has been observed.
First observed in attacks in June 2022, BianLian was seen targeting critical infrastructure organizations and private entities in the US and abroad. The group has been stealing victim data, using it for extortion.
First observed in attacks in June 2022, BianLian was seen targeting critical infrastructure organizations and private entities in the US and abroad. The group has been stealing victim data, using it for extortion.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Utilizing a PowerShell implementation of the BianLian GO backdoor, the attacker executed a series of malicious commands.
Since June 2022, BianLian ... shifted tactics from data encryption to solely data exfiltration after Avast released a decryption tool in January 2023.
Since June 2022, BianLian ... shifted tactics from data encryption to solely data exfiltration after Avast released a decryption tool in January 2023.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
At a first look, it seemed clear that the APK was heavily obfuscated... It seems to mostly rely on generating a variety of random functions to hide the real functionalities of the sample... Most of the strings in the code are generated by using functions implementing a XOR decryption of byte arrays.
The BianLian sample installs fine on Android 8. The (fake) server BianLian communicates to a C&C via HTTP. | BianLian communicates to a C&C via HTTP.
184 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
85 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in the context of Android malware abusing accessibility services. The reference does not identify it as ransomware or provide additional family-specific details.
Likely Russia-based extortion operation that shifted from double-extortion ransomware to exclusively stealing data and threatening publication after a free decryptor became available.
Ransomware family mentioned as possibly linked to the crypting actor hiddenroot.
Ransomware family mentioned as one of the criminal services hosted by Aeza Group infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.