bianlian logo

bianlian

2 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Hydra
Ver en IntelTracker → APTTrail →
BianLian is a financially motivated cybercriminal group that originated as an Android banking trojan in 2019 before transitioning to a ransomware strain in July 2022. The group, which is likely based in Russia with multiple Russia-based affiliates, quickly adapted its operations, initially employing a double-extortion model involving both data encryption and exfiltration. Following the release of a public decryptor in early 2023, BianLian swiftly pivoted its strategy to focus primarily on data exfiltration and extortion without encryption, a method it exclusively adopted by January 2024. This adaptability, reflected in its name derived from the Chinese 'face-changing' art, distinguishes BianLian as it continuously evolves its tactics and procedures to maintain operational effectiveness and pressure victims into paying ransoms.
Malware asociado
CHOPSTICK, OSX_OCEANLOTUS.D, Backdoor.Oldrea
Tecnicas MITRE
T1218, T1127, T1562, TA0027, T1082, T1027
CVEs relacionadas
CVE-2025-42999, CVE-2025-42980, CVE-2025-42966, CVE-2025-42964, CVE-2025-42963, CVE-2025-31324

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

AfghanistanAngolaArgentinaAustriaAustraliaBelgiumBahrainBrazilCanadaSwitzerland

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingSoftware PublishersTransit and Ground Passenger TransportationReal EstateHospitalsAccommodationAir TransportationManufacturingConstruction

URLs nuevas detectadas en IntelTracker

github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: bianlian (1 notes from ThreatLabz)18 Jun 2026
Report
bianlian - Ransom NotesEste grupo de ransomware tiene 1 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de resc…