◇ SIGN IN
← all actors
ransomware

BianLian

activemedium confidence
Ransomware
BianLian Ransomware GroupBianLian Data Extortion Group
Attribution
Financially motivated (unattributed; assessed Russia-based)
Origin
Russia (assessed)
First seen
2022
Last active
2025
Motivation
Financially motivated (ransomware / data extortion)
Confidence
medium
MENA targeting
Bahrain
Sectors
Maritime/industrial

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Bahrain (Maritime/industrial sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

BianLian is a financially motivated developer, deployer and data-extortion group active since June 2022, subject of repeated CISA/FBI/ASD advisories, which shifted from double extortion to exclusively exfiltration-based extortion by early 2024.

History

BianLian emerged in June 2022 and has affected organizations across multiple US critical-infrastructure sectors, with CISA assessing the group as likely based in Russia with Russia-based affiliates. It initially used a double-extortion model (encrypt after exfiltration) but shifted primarily to exfiltration-based extortion around January 2023 and to exclusively data-theft extortion around January 2024.

Documented tradecraft (per CISA/FBI/ASD's ACSC #StopRansomware advisories, originally May 2023 and updated through 2024) includes gaining access via valid RDP credentials and exploitation of internet-facing systems, exploitation of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) with web shell installation on Exchange, and use of tools such as Rclone, Mega and FTP for data exfiltration. The group pressures victims with threats to publish stolen data on its leak site.

BianLian has remained active into 2025 and continues to appear in extortion tracking. In a MENA context it has an associated claim involving Bahrain. As with all leak-site listings, individual victim claims should be treated as unverified unless independently confirmed by a reputable source or the affected organization.

Notable campaigns

2023
#StopRansomware: BianLian advisory (AA23-136A)
CISA/FBI/ACSC advisory detailing BianLian TTPs and IOCs; documented shift toward data extortion.
2024
Updated BianLian advisory
November 2024 CISA update reflecting exclusive exfiltration-based extortion and new TTPs.

Known tooling · Ransomware Tool Matrix

Tools observed in intrusions leading to BianLian's ransomware, per the community Ransomware Tool Matrix — observed use, not exhaustive. Snapshot 2026-08-07.

Discovery · 5
Advanced IP ScannerPingCastleSharpSharesSoftPerfect NetScanWKTools
RMM Tools · 6
AmmyyAdminAnyDeskAteraScreenConnectSplashtopTeamViewer
Credential Theft · 1
RDP Recognizer
OffSec · 1
Impacket
LOLBAS · 1
PsExec
Exfiltration · 2
MEGARClone

2 source reports · latest 26 March 2025

Claimed victims · 552 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
Collins Aerospace (An RTX Business)Manufacturing
CMC Technology GroupVNTechnology
Meridian SeniorUSHealthcare
Saunders and SaundersGBProfessional Services
Sonrisas Dental HealthUSHealthcare
AllworxUSTechnology
Minnesota OrthodonticsUSHealthcare
Mosley Glick O’Brien, Inc.USFinancial Services
Legal Aid Society of Salt LakeUSGovernment & Defense
Ewald ConsultingUSProfessional Services
Island RealtyUSProfessional Services
Goshen Medical CenterUSHealthcare