Bianlian
Aliases: Hydra
- First seen
- 2021-12-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-21 20:25:04
- Profile updated
- 2026-07-07 13:48:56
Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector manufacturing technology-and-telecommunications
Context
BianLian used subtle techniques to exploit, enumerate, and move laterally in victim networks to remain undetected and aggressively worked to counter Endpoint Detection & Response (EDR) protections during the encryption phase of their operations. The group has displayed signs of being new to the practical business aspects of ransomware and associated logistics. Generally they seemed to be experiencing the growing pains of a group of talented hackers new to this aspect of criminal extortion. Infrastructure associated with the BianLian group first appeared online in December 2021 and their toolset appears to have been under active development since then. Finally, we have observed the BianLian threat actor tripling their known command and control (C2) infrastructure in the month of August, suggesting a possible increase in the actor’s operational tempo.
Used by threat actors
- BianLian Group 2024 Activity (campaign)
Related threat objects
- Hydra (malware)
Reports & references
- blog.cyble.com — Bianlian New Ransomware Variant On The Rise (report)
- blogs.blackberry.com — Bianlian Ransomware Encrypts Files In The Blink Of An Eye (report)
- cryptax.medium.com — Android Bianlian Payload 61Febabed00A (report)
- cryptax.medium.com — Bianlian C C Domain Name 4F226A29E221 (report)
- cryptax.medium.com — Creating A Safe Dummy C C To Test Android Bots Ffa6E7A3Dce5 (report)
- cryptax.medium.com — Multidex Trick To Unpack Android Bianlian Ed52Eb791E56 (report)
- cryptax.medium.com — Quick Look Into A New Sample Of Android Bianlian Bc5619Efa726 (report)
- redacted.com — Bianlian Ransomware Gang Gives It A Go (report)
- rhisac.org — Bianlian Ransomware Expanding C2 Infrastructure And Operational Tempo (report)
- twitter.com — 1558548947584548865 (report)
- fortinet.com — New Wave Bianlian Malware (report)
- threatfabric.com — Bianlian From Rags To Riches The Malware Dropper That Had A Dream (report)
- virusbulletin.com — Vb2022 Hunting The Android Bianlian Botnet (report)
- virusbulletin.com — Vb2022 Hunting The Android Bianlian Botnet (report)
- youtube.com — Watch (report)
- fortinet.com — New Wave Bianlian Malware (report)
- ransomlook.io — Bianlian (report)