Ransomware Group intelligence
Bianlian
InactiveTrack Bianlian with 558 published victims and 3 known leak locations in a single intelligence view.
Overview
Bianlian is tracked by Breach House as a ransomware group with 558 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 6m ago | bianlivemqbawcco4cx4a672k2fip3guyxudzurfqvdszafam3ofqgqd.onion |
| Leak location 3 | Onion service | Down checked 6m ago | bianliaoxoeriowgqohcly4a6sbkpc3se2yvxgidxomxlpuhx5ehrpad.onion |
| Leak location 1 | Onion service | Down checked 13m ago | bianlianlbc5an4kgnay3opdemgcryg2kpfcbgczopmm3dnbz3uaunad.onion |
Top Activity Sectors (17)
- Communication / Marketing 88
- Healthcare / Pharma 75
- Services 69
- Finance / Legal / Insurance 66
- Not identified 59
- Construction / Real Estate 44
- Manufacturing / Engineering 33
- IT 26
- Transportation / Travel / Logistics 22
- Education 20
- Energy 11
- Hospitality / Food & Beverage / Tourism 9
- Public Sector 8
- Retail / E-commerce 8
- Telecommunications 5
- Agriculture / Food 4
- NGOs / Associations 2
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Bianlian, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: bianlian uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: bianlian modifies registry run keys to ensure ransomware reactivation after system reboots for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: bianlian disables antivirus tools and security software to evade detection during initial compromise and execution.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: bianlian deletes Volume Shadow Copies and backup directories via command-line tools to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: bianlian uses remote system discovery to map victim infrastructure and identify high-value targets for encryption.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1049 System Network Connections Discovery Discovery
What they do: bianlian queries system network connections to identify active services and communication paths for exfiltration or command channels.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: bianlian performs network share discovery to identify victim file shares and target data for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: bianlian exploits SMB/Windows Admin Shares to move laterally within victim networks to additional hosts.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: bianlian exfiltrates stolen data using encrypted channels to enable double extortion against victims.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: bianlian encrypts victim files using custom ransomware binaries to maximize impact and pressure for payment.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Tools Observed (17)
▼Software Bianlian has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
Look at this instruction.txt
Your network systems were attacked and encrypted. Contact us in order to restore your data. Don't make any changes in your file structure: touch no files, don't try to recover by yourself, that may lead to it's complete loss. To contact us you have to download "tox" messenger: https://qtox.github.io/ Add user with the following ID to get your instructions: A4B3B0845DA242A64BF17E0DB4278EDF85855739667D3E2AE8B89D5439015F07E81D12D767FC Alternative way: [email protected] Your ID: [snip] You should know that we have been downloading data from your network for a significant time before the attack: financial, client, business, post, technical and personal files. In 10 days - it will be posted at our site http://bianlianlbc5an4kgnay3opdemgcryg2kpfcbgczopmm3dnbz3uaunad.onion / http://bianlivemqbawcco4cx4a672k2fip3guyxudzurfqvdszafam3ofqgqd.onion with links send to your clients, partners, competitors and news agencies, that will lead to a negative impact on your company: potential financial, business and reputational loses. ---!!!---
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (558)
Search, filter and paginate the victim timeline for Bianlian. Showing 501–558 of 558.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | *** Technologies id4721 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | **i* **s**** id4720 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | **a***** H****** ******r**** id4719 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | B****** *b* id4718 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | VANOSS Public School id4676 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Power Plant Services LLC id4675 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Samrin Services Pvt Ltd id4674 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Altec Engineering LLC id4673 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Block Buildings LLC id4672 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Badger Truck Refrigeration, Inc id4671 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Myton School id4658 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Modular Mining id4657 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Centura College id4656 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Versah id4655 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Gazelle International Ltd id4654 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Boon Tool Co id4653 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rentz Management id4652 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Harry Rosen id4651 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Läderach id4431 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Veritas Solicitors id4301 View details | Other | — | ||
|
Veritas Solicitors LLP is a law firm based in Manchester, England, with its head office at Cardinal House on St Mary’s Parsonage. It offers legal services across areas including personal injury, housing disrepair, immigration and financial claims. The firm presents itself as a specialist practice focused on tailored advice and client case handling. It was listed as a ransomware victim associated with bianlian. |
|||||
| Ransomware | Meisenkothen id4300 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Dorsey metrology id4297 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BMW of Sherman Oaks id4296 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | McGann Facial Design id4295 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mayfield School id4294 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Peter Duffy Ltd id4286 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sunflower Farms Distributors, Inc id4285 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Aarti Drugs Ltd id4284 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Berg Kaprow Lewis id4283 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Company, LLC id4282 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | derach id4281 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Seanic Ocean Systems id4280 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bartelt id4279 View details | Hospitality / Food & Beverage / Tourism | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Aesthetic Dermatology Associates id4273 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Spa id4141 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Baer's id4077 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Infinitely Virtual id4076 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Magnachem id4056 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Alegria Family Services id4055 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | WWAY-TV, LLC id4054 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ramada Hervey Bay Hotel Resort id4053 View details | Hospitality / Food & Beverage / Tourism | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Community Dental Partners id4052 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | 4cRisk id4051 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Captec-group id4050 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Spalding Grammar School id4047 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rudman id4046 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The Preston Partnership id4045 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Advance Corporation id4044 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | International Custom Controls id4043 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | .com id3823 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ISGEC Heavy Engineering id3800 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | VERITAS Solicitors id3799 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Conway Electrics id3798 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rain the Growth Agency id3795 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mackenzie Medical id3783 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Anderson Insurance Associates id3782 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | High Power Technical Services id3781 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mooresville Schools id3780 View details | Education | — | ||
|
No additional victim description available. |
|||||