Back to Ransomware Database
Ransomware Group
bianlian
BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog.
Known victims552
Threat Level
CRITICAL
Tactics, Techniques & Procedures (TTPs)
CredentialTheft
- RDP Recognizer
DiscoveryEnum
- Advanced IP Scanner
- Advanced Port Scanner
- PingCastle
- SharpShares
- SoftPerfect NetScan
- +1 more
Exfiltration
- MEGA
- RClone
LOLBAS
- PsExec
Offsec
- Impacket
RMM-Tools
- AmmyyAdmin
- AnyDesk
- Atera
- ScreenConnect
- Splashtop
- +1 more
Indicators of Compromise (IOCs)
IP Addresses
191- 88.212.241.105
- 91.245.255.27
- 162.33.179.99
- 151.236.16.144
- 172.96.137.108
- 31.220.80.82
- 104.238.35.179
- 151.236.16.242
- 104.238.35.179
- 85.235.151.5
- 5.255.106.12
- 23.227.198.237
- 5.255.106.12
- 98.82.12.229
- 172.96.137.32
- +176 more
Get Complete IOC Feed
Access our full IOC database via API for integration with your SIEM/SOAR.
Get StartedNo credit card required · Free API key
Check If You're Affected
Search our database to see if your organization appears in bianlian's victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request