- First observed: June/July 2022
- Believed origin: Russia (likely; FBI/CISA/ACSC assess Russia-based affiliates)
- Model: Started as double-extortion ransomware, then data-theft-only extortion
- Status: Active
Origin
BianLian takes its name from a centuries-old Sichuan opera art form in which performers change ornate masks in the blink of an eye. The name may also be a disguise. In their joint advisory, the FBI, CISA, and the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) noted that they are "aware of multiple ransomware groups, like BianLian, that seek to misattribute location and nationality by choosing foreign-language names, almost certainly to complicate attribution efforts." The same advisory describes BianLian as "a ransomware developer, deployer, and data extortion cybercriminal group, likely based in Russia, with multiple Russia-based affiliates."
The group's earliest activities weren't ransomware. Threat intelligence firm S-RM traced its evolution from an Android banking trojan, to a double-extortion ransomware operation, to a group that only steals data. S-RM also cautioned that little is known about its affiliates or internal structure.
Sector preference for sensitive data
BianLian's targeting is driven by the value of the data victims hold rather than by ideology. S-RM describes it as financially motivated and opportunistic, with a focus on sectors that handle sensitive information, especially healthcare and legal services. The joint advisory reported that the site listed 118 past targets, with healthcare the largest sector. About 71% of the targets were in the U.S., 11% in the UK, and 7% in Australia.
The group's ransom notes, reproduced in the advisory, show how deliberately it targets sensitive data. One note warns that "leaking of folders like 'Personal Data' is a disclosure of personal and medical information of people that intrusted [sic] you to keep it." For a healthcare organization, that is a direct threat to patients.
The notes also describe the group as "BianLian team. Financial motivation only." and tell victims to "Embrace it and pay us." They even try to reassure victims about the group's reliability: "Our business depends on the reputation even more than many others." The FBI and CISA give the opposite advice, they "do not encourage paying ransom, as payment does not guarantee victim files will be recovered."
Early momentum
BianLian's growth was visible almost from the start. In a September 2, 2022 report, Dark Reading described the group as a newcomer to the ransomware scene that was already ramping up activity, with victims in Australia, North America, and the United Kingdom.
According to Dark Reading, the firm Redacted saw a troubling increase in how quickly BianLian was bringing new command-and-control servers online, which suggested the operators might be preparing to work at a faster pace. The researchers admitted they couldn't pin down the exact cause of the surge, but noted that a ransomware operator with more resources is never good news for defenders.
Why BianLian stopped encrypting files
BianLian changed its operating model in response to one piece of free security tooling. In January 2023, antivirus company Avast released a free decryption tool that let victims unlock their files without paying, taking away the group's leverage. Picus Security's analysis describes BianLian responding by shifting to exfiltration and extortion without encryption. According to the advisory, BianLian "originally employed a double-extortion model in which they encrypted victims' systems after exfiltrating the data; however, they shifted primarily to exfiltration-based extortion around January 2023 and shifted to exclusively exfiltration-based extortion around January 2024." Prior to January 2024, the encryptor also tagged locked files with a .bianlian extension and dropped a ransom note in every affected directory.
How the group gets in and steals
The advisory notes BianLian's playbook, "The group gains access to victim systems through valid Remote Desktop Protocol (RDP) credentials, uses open-source tools and command-line scripting for discovery and credential harvesting, and exfiltrates victim data via File Transfer Protocol (FTP), Rclone, or Mega."
Those RDP credentials are likely bought from initial access brokers or obtained through phishing. The November 2024 update added that "BianLian group actors target public-facing applications of both Windows and ESXi infrastructure, possibly leveraging the ProxyShell... exploit chain to gain initial access." Once inside, the group moves laterally with PsExec and RDP using valid accounts, and it has been observed disabling antivirus tools along the way.
The 2022 reporting shows this approach was already taking shape in the group's earliest campaigns. Dark Reading noted that the ransomware was written in Go, a language that lets attackers tweak a single codebase and compile it for multiple platforms. In those early attacks, the group exploited the ProxyShell Exchange Server vulnerability chain (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) and also targeted SonicWall VPN devices. Once inside, Dark Reading reported, the operators leaned on built-in Windows utilities such as net.exe, netsh.exe, and reg.exe to change user permissions, adjust firewall settings, and alter remote desktop and security policy configurations. They also deployed a custom backdoor that fetches payloads from a remote server and runs them in memory, and researchers described the group as skilled at adapting its lateral movement to the defenses it met.
Its encryption-era tradecraft was built to dodge detection as well. Dark Reading reported that, like several other cross-platform ransomware families, BianLian could restart machines in Windows Safe Mode to run its encryptor unnoticed, and that it deleted snapshots, purged backups, and launched its encryption module through Windows Remote Management and PowerShell scripts.
Besides technical intrusion, the group also uses psychological pressure on employees. The advisory says the group "engages in additional techniques to pressure the victim into paying the ransom; for example, printing the ransom note to printers on the compromised network. Employees of victim companies have also reported receiving threatening telephone calls from individuals associated with BianLian group."
The 2025 mail campaign
On March 6, 2025, the FBI issued a public service announcement warning of a scam involving letters delivered by mail to corporate executives, "claiming to have come from a ransomware group."
According to the FBI, the letters are "Stamped 'Time Sensitive Read Immediately'" and claim that the "BianLian Group" gained access to the organization's network and stole thousands of sensitive data files. The letter threatens to publish the data to BianLian's leak sites unless the recipient pays between $250,000 and $500,000 within ten days of receipt, using an included QR code linked to a Bitcoin wallet. It also claims the group will not negotiate further. The letters carry a U.S.-based return address of "BianLian Group" originating from Boston, Massachusetts.
The FBI did not believe these letters came from the real group. The alert states, "FBI assesses the letters are an attempt to scam organizations into paying a ransom," and adds, "We have not yet identified any connections between the senders and the widely-publicized BianLian ransomware and data extortion group." Real BianLian operators steal data through compromised RDP credentials and exfiltration tools. These impostors apparently stole nothing, relying on the group's name and a paper deadline to frighten executives into paying.
Read also: CISA confirms BianLian ransomware abandoned encryption for pure data theft
FAQs
What is an advisory in cybersecurity?
A cybersecurity advisory is an official alert from government agencies or security organizations that describes a threat and how to defend against it.
What is a command-and-control (C2) server?
A command-and-control server is a system attackers use to send instructions to compromised machines and receive stolen data from them.
What does "attribution" mean in cybersecurity?
Attribution is the process of identifying who is behind a cyberattack.
