Also known as: BianLian Group, BianLian Ransomware Group, Bitter Scorpius
Profile generated with AI assistance — review before citing.
Exploit Public-Facing Application
Exploit vulnerabilities in internet-facing applications to gain access.
External Remote Services
Abuse remote services like VPNs or RDP to gain access to the network.
Valid Accounts
Use legitimate credentials to authenticate and gain access.
Phishing
Send deceptive messages to trick victims into executing malicious content.
T1078.003
T1021.004
T1053.005
T1543.003
T1136.001
T1136.002
T1070.004
T1070.001
T1027.002
T1112
T1562.001
T1003.003
T1555.003
T1087.001
T1087.002
T1482
T1049
T1069.001
T1069.002
T1057
T1033
T1048.003
T1567.002
T1588.002
T1590
T1505.003
T1505.004
T1571
T1530
T1505.005
T1552.001
T1201
T1020
T1036.004
T1098
T1136.003
T1003.002
T1552.004
T1587.001
T1012
T1115
T1537
T1090.002
Malware used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Malware used by BianLian.
Legitimate tool used by BianLian.
Malware used by BianLian.
Legitimate tool used by BianLian.
Legitimate tool used by BianLian.
Malware used by BianLian.
Custom Go-based ransomware and backdoor used before shift to extortion-only model
Backup software exploited to access and exfiltrate backup data
| Type | Value |
|---|---|
| domain | bianlian2t7y7vgo[.]onion |
| domain | bianlianlbc5an4kgnay[.]onion |
| hash | 34b1c7e5d682fafb6da1d03b353c964e6cf15dd37ad1f6fbe79ea7a9b2f44f10 |
| hash | 80dcbc2ad3eab31938b2b573dd0cd36ea7b7f7c5f3e8e7b3c5a1d8e0f5c7e9f8 |
| hash | c7c5d7f8e9f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7 |
| ip | 45[.]227[.]253[.]50 |
| ip | 193[.]56[.]146[.]165 |
| domain | logcenter[.]online |
| url | hxxp[://]185[.]225[.]73[[.]]244:8080/update |
| hash | 5f4dcc3b5aa765d61d8327deb882cf99 |
| hash | 7b15f570a23a5c5ce8ff942da60834a9d0549ea3ea9f34f900a09331325df893 |
| hash | 1fd07b8d1728e416f897bef4f1471126f9b18ef108eb952f4b75050da22e8e43 |
| hash | 0c1eb11de3a533689267ba075e49d93d55308525c04d6aff0d2c54d1f52f5500 |
| hash | 40126ae71b857dd22db39611c25d3d5dd0e60316b72830e930fba9baf23973ce |
| ip | 184[.]174[.]96[.]74 |
| ip | 184[.]174[.]96[.]70 |
| ip | 45[.]144[.]225[.]22 |
| ip | 185[.]234[.]217[.]84 |
| ip | 192[.]145[.]112[.]98 |
| domain | bianlian2tcvlzhixu6oxy2hpwpljzqdm4cc42ty7kxu73yopaofvyqd[.]onion |
| domain | bianlianlbc5an4kgnay3opdemgcryg2kpfcbgczopmm3dnbz3uaunad[.]onion |
#StopRansomware: BianLian Ransomware Group - CISA Alert (AA23-136A)
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-136a
BianLian Ransomware Group - FBI Flash Report
https://www.ic3.gov/Media/News/2023/230510.pdf
BianLian Ransomware Shifts to Pure Extortion Model - Redacted Team Analysis
https://www.redacted.com/blog/bianlian-ransomware-gang-gives-up-on-encryption-focuses-on-extortion/
BianLian Ransomware Group Technical Analysis - Unit 42
https://unit42.paloaltonetworks.com/bianlian-ransomware/
BianLian: A New Ransomware Group on the Rise - Cyble Research
https://blog.cyble.com/2022/08/11/bianlian-a-new-ransomware-group-on-the-rise/
BianLian Ransomware Analysis and Decryptor Release - Avast
https://decoded.avast.io/threatresearch/bianlian-ransomware-analysis-and-decryptor-release/
MITRE ATT&CK Group: BianLian
https://attack.mitre.org/groups/G1046/
BianLian Ransomware Group Profile - The DFIR Report
https://thedfirreport.com/2023/01/09/unwrapping-bianlians-gift/
Trend Micro: BianLian Ransomware Analysis
https://www.trendmicro.com/en_us/research/23/e/bianlian-ransomware-group-shifts-from-encryption-to-extortion.html
Redacted Security: BianLian Ransomware Group
https://redacted.com/blog/bianlian-ransomware-group/
Redacted Team Analysis - BianLian Ransomware Group
https://redacted.com/blog/bianlian-ransomware-gang-gives-it-a-go/
Unit 42 - From Ransomware to Pure Extortion: Examining the Shift in BianLian's TTPs
https://unit42.paloaltonetworks.com/bianlian-ransomware-group-overview/
BianLian Group Threat Analysis
https://www.cybereason.com/blog/threat-analysis-report-bianlian-ransomware
Redacted Team Analysis of BianLian Ransomware Group
https://redacted.com/blog/bianlian-ransomware-gang-gives-up-on-encryption-now-focused-only-on-theft-and-extortion/
Redacted Team Analysis of BianLian Ransomware Group
https://redacted.com/blog/bianlian-ransomware-group-analysis/
Arctic Wolf: Self-Proclaimed BianLian Group Uses Physical Mail to Extort Organizations
https://arcticwolf.com/resources/blog/self-proclaimed-bianlian-group-uses-physical-mail-to-extort-organizations/
FBI IC3 Alert: Mail Scam Targeting Corporate Executives Claims Ties to Ransomware (March 2025)
https://www.ic3.gov/PSA/2025/PSA250306-2
Rapid7 Blog: Fake BianLian Ransomware Letters in Circulation
https://www.rapid7.com/blog/post/2025/03/19/fake-bianlian-ransomware-letters-in-circulation/
Unit 42 Palo Alto Networks: BianLian Ransomware Group Threat Assessment (June 2024)
https://unit42.paloaltonetworks.com/bianlian-ransomware-group-threat-assessment/
Picus Security: BianLian's Shape-Shifting Tactics: From Encryption to Pure Extortion (December 2024)
https://www.picussecurity.com/resource/blog/bianlians-shape-shifting-tactics-from-encryption-to-pure-extortion
Juniper Networks: BianLian Ransomware Group 2024 Activity Analysis
https://blogs.juniper.net/en-us/security/bianlian-ransomware-group-2024-activity-analysis
Unit 42: Extortion and Ransomware Trends January-March 2025
https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/
Surefire Cyber: Threat Actor Deep Dive: BianLian (March 2025)
https://www.surefirecyber.com/threat-actor-deep-dive-bianlian/
Redline Stealer, Meet BianLian Group - Unit 42
https://unit42.paloaltonetworks.com/threat-brief-bianlian-ransomware-group/
BianLian Ransomware Shifts Strategy - Cyberint
https://cyberint.com/blog/research/bianlian-ransomware-gang-gives-up-encryption-focusing-purely-on-extortion/
Redline Threat Intelligence - BianLian Analysis
https://redline.tech/2023/05/15/bianlian-ransomware-group-continues-to-evolve/