Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1562.001 ↗inferred | Impair Defenses: Disable or Modify Tools | Defense Evasion | disables antivirus and defenses via PowerShell (CISA AA23-136A) |
| T1048 ↗inferred | Exfiltration Over Alternative Protocol | Exfiltration | uses FTP for data exfiltration (CISA AA23-136A) |
| T1567.002 ↗inferred | Exfiltration Over Web Service: Exfiltration to Cloud Storage | Exfiltration | uses Rclone and Mega for exfiltration (CISA AA23-136A) |
| T1490 ↗inferred | Inhibit System Recovery | Impact | documented ransomware recovery inhibition (CISA AA23-136A) |
| T1486 ↗inferred | Data Encrypted for Impact | Impact | early double-extortion encryption before shift to pure data extortion (CISA AA23-136A) |
| T1133 ↗inferred | External Remote Services | Initial Access | uses RDP to internet-facing systems (CISA AA23-136A) |
+10 more relationships — see the relationships browser.
| T1190 ↗inferred | Exploit Public-Facing Application | Initial Access | exploited ProxyShell on Exchange (CISA AA23-136A) |
| T1078 ↗inferred | Valid Accounts | Initial Access | gains access via valid RDP credentials (CISA AA23-136A) |
| T1021.001 ↗inferred | Remote Services: Remote Desktop Protocol | Lateral Movement | uses RDP for lateral movement (CISA AA23-136A) |
| T1505.003 ↗inferred | Server Software Component: Web Shell | Persistence | installs web shells on Exchange after ProxyShell (CISA AA23-136A) |
Regional co-occurrence is association, not prediction. These techniques appeared alongside BianLian's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter BianLian's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.