White Paper
THREAT PROFILE: BianLian Ransomware
BianLian is a cybercriminal group first identified in 2022 that evolved from a ransomware-as-a-service (RaaS) operation into a data extortion-focused threat actor. While the group originally combined file encryption with data theft, it shifted in 2023 toward primarily stealing sensitive information and extorting victims without relying heavily on ransomware encryption. However, encryption has still been observed in some attacks. BianLian targets organizations across multiple industries and regions, using stolen data as leverage by threatening public disclosure if ransom demands are not met. This threat profile examines the group’s preferred targets, known exploited vulnerabilities, associated threat actors, attack tools, and observed behaviors in Windows environments. It also maps BianLian
