Skip to main content
Back to Ransomware Database
Ransomware Group

bianlian

BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog.

Known victims552

Threat Level

CRITICAL

Tactics, Techniques & Procedures (TTPs)

CredentialTheft

  • RDP Recognizer

DiscoveryEnum

  • Advanced IP Scanner
  • Advanced Port Scanner
  • PingCastle
  • SharpShares
  • SoftPerfect NetScan
  • +1 more

Exfiltration

  • MEGA
  • RClone

LOLBAS

  • PsExec

Offsec

  • Impacket

RMM-Tools

  • AmmyyAdmin
  • AnyDesk
  • Atera
  • ScreenConnect
  • Splashtop
  • +1 more

Indicators of Compromise (IOCs)

IP Addresses

191
  • 88.212.241.105
  • 91.245.255.27
  • 162.33.179.99
  • 151.236.16.144
  • 172.96.137.108
  • 31.220.80.82
  • 104.238.35.179
  • 151.236.16.242
  • 104.238.35.179
  • 85.235.151.5
  • 5.255.106.12
  • 23.227.198.237
  • 5.255.106.12
  • 98.82.12.229
  • 172.96.137.32
  • +176 more

Get Complete IOC Feed

Access our full IOC database via API for integration with your SIEM/SOAR.

Get Started

No credit card required · Free API key

0

Check If You're Affected

Search our database to see if your organization appears in bianlian's victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request

Other Active Ransomware Groups