Bianlian

Inactive
BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog.
552 Victims
Jul 13, 2022 First Discovered
Mar 31, 2025 Last Discovered
534 Days Inactive
0% Infostealer
0/3 Sites Online
Known Locations (3)
BianLian | Home
bianlianlbc5an4kgnay3opdemgcryg2kpfcbgczopmm3dnbz3uaunad.onion
bianliaoxoeriowgqohcly4a6sbkpc3se2yvxgidxomxlpuhx5ehrpad.onion
BianLian | Home
bianlivemqbawcco4cx4a672k2fip3guyxudzurfqvdszafam3ofqgqd.onion
Tools Used
CredentialTheft
RDP Recognizer
DiscoveryEnum
Advanced IP Scanner, Advanced Port Scanner, PingCastle, SharpShares, SoftPerfect NetScan, WKTools
Exfiltration
MEGA, RClone
LOLBAS
PsExec
Offsec
Impacket
RMM-Tools
AmmyyAdmin, AnyDesk, Atera, ScreenConnect, Splashtop, TeamViewer
Intelligence
Victims (552)

Detailed victim list temporarily unavailable

This group has 552 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.