Netskope Threat Labs

BianLian

ATP Sandbox Adv. HeuristicsAV

BianLian is a Go based ransomware operation that breaches organizations across several industries and demands large ransom amounts. Its operators gained access through valid remote desktop credentials, used open source tools and command line scripting for reconnaissance and credential harvesting, and exfiltrated data over FTP, Rclone, or Mega. The group originally paired encryption with data theft, but around January 2023 it shifted primarily to extortion based on stolen data alone.

First seen
September 2022
Last seen
October 2026
Bianlian
Alert Name
Trojan.Ransom.BianLian.A
Trojan.Ransom.BianLian.C
Trojan.Ransom.BianLian.D
Trojan.Ransom.BianLian.E
Win32.Trojan.Bianlian
Win64.Ransomware.Bianlian
Win64.Ransomware.BianLian
Win64.Trojan.Bianlian