BianLian — Ransomware Profile
BianLian shifted from encryption-based ransomware to pure data extortion in 2023, primarily targeting US healthcare and professional services organizations.Tools & malware
- Advanced Port Scanner discovery
- AnyDesk remote access / RMM
- Atera Agent remote access / RMM
- BianLian encryptor (Go) ransomware
- BianLian Go backdoor backdoor
- FTP exfiltration
- Impacket credential access / lateral movement
- Mega exfiltration
- ngrok tunneling / C2
- PingCastle discovery (Active Directory)
- PsExec lateral movement
- Rclone exfiltration
- Rsocks tunneling / proxy
- SharpShares discovery (network shares)
- SoftPerfect Network Scanner discovery
- SplashTop remote access / RMM
- TeamViewer remote access / RMM
Recent claimed victims
- Sonrisas Dental Health 2025-03-31
- CMC Technology Group 2025-03-31
- Saunders and Saunders 2025-03-31
- Meridian Senior 2025-03-31
- Goshen Medical Center 2025-03-22
- Island Realty 2025-03-07
- Allworx 2025-03-07
- Minnesota Orthodontics 2025-03-07
- Ewald Consulting 2025-03-04
- Legal Aid Society of Salt Lake 2025-03-04
- Mosley Glick O’Brien, Inc. 2025-03-04
- Keystone Pacific Property Management LLC 2025-03-04
- Alabama Ophthalmology Associates 2025-02-19
- Aspire Rural Health System 2025-02-13
- Nippon Steel USA 2025-02-13
- Financial Services of America, Inc. 2025-02-13
- Dain, Torpy, Le Ray, Wiest & Garner, P.C. 2025-02-13
- Nash Brothers Construction 2025-02-13
- Layfield & Borel CPA's L.L.C 2025-02-13
- Recievership Specialists 2025-02-10
- D-7 Roofing 2025-02-10
- NESCTC Security Services 2025-02-05
- Dash Business 2025-02-05
- Hall Chadwick 2025-02-05
- C & R Molds Inc 2025-02-04
Vendor research
- #StopRansomware: BianLian Ransomware Group (AA23-136A) CISA / FBI / ACSC
- BianLian Ransomware Gang Gives It a Go! Redacted
- Threat Assessment: BianLian Palo Alto Networks Unit 42
- FBI confirms BianLian ransomware switch to extortion only attacks BleepingComputer
- CISA says BianLian ransomware now focuses only on data theft BleepingComputer