BianLian (Android)
Aliases: Hydra
- First seen
- 2021-09-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-18 23:17:52
- Profile updated
- 2026-07-07 13:49:00
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Context
BianLian is an Android banking trojan known for targeting financial institutions by stealing user credentials. Often distributed via phishing campaigns, it is also referred to as Hydra and poses a significant threat to mobile banking users.
Reports & references
- cryptax.medium.com — Android Bianlian Payload 61Febabed00A (report)
- cryptax.medium.com — Bianlian C C Domain Name 4F226A29E221 (report)
- cryptax.medium.com — Creating A Safe Dummy C C To Test Android Bots Ffa6E7A3Dce5 (report)
- cryptax.medium.com — Multidex Trick To Unpack Android Bianlian Ed52Eb791E56 (report)
- cryptax.medium.com — Quick Look Into A New Sample Of Android Bianlian Bc5619Efa726 (report)
- threatfabric.com — Bianlian From Rags To Riches The Malware Dropper That Had A Dream (report)
- youtube.com — Watch (report)
- fortinet.com — New Wave Bianlian Malware (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Bianlian (report)
- cryptax.medium.com — Bad Zip And New Packer For Android Bianlian 5Bdad4B90Aeb (report)