Uptime Hamster: 10d 9h 54mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza bianlian

bianlian

3 incidentes 1 paises 1 sectores ransomware RU Ultimo: 2026-06-29
Aliases: Hydra
Ver en IntelTracker → APTTrail →
BianLian is a financially motivated cybercriminal group that originated as an Android banking trojan in 2019 before transitioning to a ransomware strain in July 2022. The group, which is likely based in Russia with multiple Russia-based affiliates, quickly adapted its operations, initially employing a double-extortion model involving both data encryption and exfiltration. Following the release of a public decryptor in early 2023, BianLian swiftly pivoted its strategy to focus primarily on data exfiltration and extortion without encryption, a method it exclusively adopted by January 2024. This adaptability, reflected in its name derived from the Chinese 'face-changing' art, distinguishes BianLian as it continuously evolves its tactics and procedures to maintain operational effectiveness and pressure victims into paying ransoms.

Aliases del actor

Hydra

Actores similares

hydra-saigaactor · 1hydraqactor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: BianLian
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: BianLian
DLS / leak siteunknownwww.welivesecurity.comBushidoUK ToolMatrix GroupProfiles: BianLian
DLS / leak siteunknownwww.cisa.govBushidoUK ToolMatrix GroupProfiles: BianLian
Repositoriounknowngithub.comRansom Notes: bianlian (1 notes from ThreatLabz)
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: bianlian
Malware asociado
CHOPSTICK, OSX_OCEANLOTUS.D, Backdoor.Oldrea
Tecnicas MITRE
T1218, T1127, T1562, TA0027, T1082, T1027
CVEs relacionadas
CVE-2025-42999, CVE-2025-42980, CVE-2025-42966, CVE-2025-42964, CVE-2025-42963, CVE-2025-31324
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

AfghanistanAngolaArgentinaAustriaAustraliaBelgiumBahrainBrazilCanadaSwitzerland

Sectores atacados

Software (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingSoftware PublishersTransit and Ground Passenger TransportationReal EstateHospitalsAccommodationAir TransportationManufacturingConstruction

URLs nuevas detectadas en IntelTracker

github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: bianlian (1 notes from ThreatLabz)18 Jun 2026
Report
bianlian - Ransom NotesEste grupo de ransomware tiene 1 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de resc…