BianLian Ransomware

Description Summary

BianLian, named after a Chinese face-changing performance art, is a Go-based ransomware family that surfaced in mid-2022. After Avast released a free decryptor in early 2023, BianLian shifted to extortion-only operations — stealing data and threatening publication without encrypting victim systems.

Threat Actor

BianLian is assessed by U.S. and Australian agencies to operate from Russia with multiple Russia-based affiliates. Initial access is typically via valid RDP credentials purchased from initial access brokers.

Technical Indicators

Encryption Extension
.bianlian (legacy; current operations are exfiltration-only)
Encryption Algorithm
AES-256 (CBC mode) — when used; many operations skip encryption entirely
Ransom Note Name
Look_at_this_instruction.txt
Targeted Industries
Healthcare, Critical manufacturing, Professional services, Financial
First Seen
June 2022
Last Seen
Active — extortion-only (encryption abandoned Jan 2024)
Geographical Location
United States, Australia, Europe

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 3 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
T1567.002 Exfiltration to Cloud Storage (Mega/Rclone/FTP)
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop