HackerFeeds
All ransomware groups

bianlian

552 tracked victims
·first seen 2022-07-14·last activity 2025-03-31

Group profile

BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog.

MITRE ATT&CK TTPs

TA0002

Execution

  • T1059Command and Scripting Interpreter

    Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.

  • T1204User Execution

    An adversary may rely upon specific actions by a user in order to gain execution.

TA0005

Defense Evasion

  • T1027.002Software Packing

    Adversaries may perform software packing or virtual machine software protection to conceal their code.

  • T1036Masquerading

    Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.

  • T1497Virtualization/Sandbox Evasion

    Adversaries may employ various means to detect and avoid virtualization and analysis environments.

TA0007

Discovery

  • T1082System Information Discovery

    An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.

  • T1083File and Directory Discovery

    Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.

  • T1120Peripheral Device Discovery

    Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.

  • T1518.001Security Software Discovery

    Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.

TA0008

Lateral Movement

  • T1091Replication Through Removable Media

    Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.

Recent victims

showing 50 of 552
DateWebsite / victimSectorCountry
2025-03-31
cmctechgroup.com
CMC Technology Groupcmctechgroup.com
TechnologyVN
2025-03-31
meridiansenior.com
Meridian Seniormeridiansenior.com
HealthcareUS
2025-03-31
sanders-sanders.co.uk
Saunders and Saunderssanders-sanders.co.uk
Business ServicesGB
2025-03-31
sonrisasdental.org
Sonrisas Dental Healthsonrisasdental.org
HealthcareUS
2025-03-22
goshenmedical.org
Goshen Medical Centergoshenmedical.org
HealthcareUS
2025-03-07TelecommunicationUS
2025-02-25
islandreality.com
Island Realtyislandreality.com
Business ServicesUS
2025-03-07
minnesotaorthodontics.com
Minnesota Orthodonticsminnesotaorthodontics.com
HealthcareUS
2025-03-04
keystonepacificpm.com
Keystone Pacific Property Management LLCkeystonepacificpm.com
Business ServicesUS
2025-03-04
mgoinc.com
Mosley Glick O’Brien, Inc.mgoinc.com
Financial ServicesUS
2025-03-04
legalaidsocietyofsaltlake.org
Legal Aid Society of Salt Lakelegalaidsocietyofsaltlake.org
Public SectorUS
2025-03-04
ewald-consulting.com
Ewald Consultingewald-consulting.com
Business ServicesUS
2025-02-19
aoapc.com
Alabama Ophthalmology Associatesaoapc.com
HealthcareUS
2025-02-13
aspirerhs.org
Aspire Rural Health Systemaspirerhs.org
HealthcareUS
2025-01-13
N
Nash Brothers Construction
ConstructionUS
2025-02-13
nipponsteel.com
Nippon Steel USAnipponsteel.com
ManufacturingUS
2025-02-13
fsa1.com
Financial Services of America, Inc.fsa1.com
Financial ServicesUS
2025-02-13
layfieldandborelcpas.com
Layfield & Borel CPA's L.L.Clayfieldandborelcpas.com
Financial ServicesUS
2025-02-13
daintorpy.com
Dain, Torpy, Le Ray, Wiest & Garner, P.C.daintorpy.com
Business ServicesUS
2025-01-07
d7roofing.com
D-7 Roofingd7roofing.com
ConstructionUS
2025-02-10
recievershipspecialists.com
Recievership Specialistsrecievershipspecialists.com
Business ServicesUS
2025-02-05
D
Dash Business
Business Services
2025-02-05Financial ServicesAU
2025-02-05
nesctc.com
NESCTC Security Servicesnesctc.com
Business ServicesUS
2025-02-04
crmolds.com
C & R Molds Inccrmolds.com
ManufacturingUS
2025-02-04
commercialsolutions.com
Commercial Solutionscommercialsolutions.com
Business ServicesUS
2025-02-02
cyrious.com
Cyrious Softwarecyrious.com
TechnologyUS
2025-02-02
mabmd.com
Medical Associates of Brevardmabmd.com
HealthcareUS
2025-02-02
civiccommittee.org
Civic Committeeciviccommittee.org
Public SectorUS
2025-02-02
ayres-law-firm.com
Ayres Law Firmayres-law-firm.com
Business ServicesUS
2025-02-02
growthaccelerationpartners.com
Growth Acceleration Partnersgrowthaccelerationpartners.com
TechnologyUS
2025-01-18
massdevelopment.com
MassDevelopmentmassdevelopment.com
Public SectorUS
2024-12-26
caframo.com
Caframo Limited.caframo.com
ManufacturingCA
2024-12-18
cottrellaw.com
Cottrell Fletcher & Cottrell P.C.cottrellaw.com
Business ServicesUS
2024-12-18
gdwlawfirm.com
Giordano, DelCollo, Werb & Gagne, LLC.gdwlawfirm.com
Business ServicesUS
2024-12-14
ace-it.com
American Computer Estimating Incace-it.com
TechnologyUS
2024-12-14
medrevenu.com
MedRevenu Incmedrevenu.com
HealthcareUS
2024-12-14
mymfpc.com
Mid Florida Primary Caremymfpc.com
HealthcareUS
2024-12-10
iglobalinsure.com
Global Insurance Agency LLCiglobalinsure.com
Financial ServicesUS
2024-12-10
ppcswfl.com
Physicians' Primary Care of Southwest Floridappcswfl.com
HealthcareUS
2024-12-06
ltitrucking.com
LTI Trucking Servicesltitrucking.com
Transportation/LogisticsUS
2024-12-05
starshuttle.com
Star Shuttle Inc.starshuttle.com
Transportation/LogisticsUS
2024-12-01
alpineent.com
Alpine Ear Nose & Throatalpineent.com
HealthcareUS
2024-11-26
twru.com
TWRU CPAs & Financial Advisorstwru.com
Financial ServicesUS
2024-11-22
trinitymgt.com
Trinity Petroleum Management, LLCtrinitymgt.com
EnergyUS
2024-11-21
kellfer.com
Kellerhals Ferguson Kroblin PLLCkellfer.com
Business ServicesUS
2024-11-21
silverbackexp.com
Silverback Explorationsilverbackexp.com
EnergyUS
2024-11-20
A
Amherstburg Family Health
HealthcareCA
2024-11-10
immunolabs.com
Immuno Laboratories, Incimmunolabs.com
HealthcareUS
2024-11-09
atsg.net
ATSG, Incatsg.net
Transportation/LogisticsUS