BianLian (Windows)
- First seen
- 2022-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:48:58
Targeted industries: healthcare-and-pharmaceutical financial-services technology-and-telecommunications government-and-public-sector professional-services manufacturing
Context
BianLian is a GoLang-based ransomware that continues to breach several industries and demand large ransom amounts. The threat actors also use the double extortion method by stealing an affected organization’s files and leaking them online if the ransom is not paid on time. BianLian gains access to victim systems through valid Remote Desktop Protocol (RDP) credentials, uses open-source tools and command-line scripting for discovery and credential harvesting, and exfiltrates victim data via File Transfer Protocol (FTP), Rclone, or Mega. BianLian originally employed a double-extortion model in which they encrypted victims’ systems after exfiltrating the data; however, around January 2023, they shifted to primarily exfiltration-based extortion. The BianLian ransomware uses goroutines and encrypts files in chunks to quickly hijack an infected system. The ransomware adds its own extension to each encrypted file.
Reports & references
- blog.cyble.com — Bianlian New Ransomware Variant On The Rise (report)
- blogs.blackberry.com — Bianlian Ransomware Encrypts Files In The Blink Of An Eye (report)
- redacted.com — Bianlian Ransomware Gang Gives It A Go (report)
- twitter.com — 1558548947584548865 (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- Cisco Talos — Talos Ir Q2 2023 Quarterly Recap (report)
- youtube.com — O2Wx7Mqhr2I (report)
- bleepingcomputer.com — March 2023 Broke Ransomware Attack Records With 459 Incidents (report)
- censys.com — A Beginners Guide To Tracking Malware Infrastructure (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Bianlian (report)
- embee-research.ghost.io — Building Advanced Censys Queries Utilising Regex Bianlian (report)
- embee-research.ghost.io — Practical Queries For Malware Infrastructure Part 3 (report)
- embeeresearch.io — Practical Queries For Malware Infrastructure Part 3 (report)