Description Summary
BianLian, named after a Chinese face-changing performance art, is a Go-based ransomware family that surfaced in mid-2022. After Avast released a free decryptor in early 2023, BianLian shifted to extortion-only operations — stealing data and threatening publication without encrypting victim systems.
Threat Actor
BianLian is assessed by U.S. and Australian agencies to operate from Russia with multiple Russia-based affiliates. Initial access is typically via valid RDP credentials purchased from initial access brokers.
Technical Indicators
Encryption Extension
.bianlian (legacy; current operations are exfiltration-only)
Encryption Algorithm
AES-256 (CBC mode) — when used; many operations skip encryption entirely
Ransom Note Name
Look_at_this_instruction.txt
Targeted Industries
Healthcare, Critical manufacturing, Professional services, Financial
First Seen
June 2022
Last Seen
Active — extortion-only (encryption abandoned Jan 2024)
Geographical Location
United States, Australia, Europe
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 3 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| T1567.002 | Exfiltration to Cloud Storage (Mega/Rclone/FTP) | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |