Detect, Respond, Protect
See how the global Huntress SOC can augment your team
with 24/7 coverage and unmatched human expertise.
Start your free trial today.
BianLian is a ransomware and data extortion group, first observed in June 2022. Likely based in Russia, the group targets critical infrastructure sectors in the U.S. and Australia. Known for their exfiltration-based extortion tactics, BianLian has shifted away from encrypting systems, focusing instead on data theft and extortion.
Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.
BianLian primarily focuses on exfiltration-based extortion, targeting sensitive data to pressure victims into paying ransoms.
Gaining access via compromised Remote Desktop Protocol (RDP) credentials.
Using open-source tools like PowerShell and command-line scripting for discovery and credential harvesting.
Exfiltrating data via FTP, Rclone, or Mega.
Deploying custom backdoors written in Go for persistence.
Disabling antivirus tools and tamper protection.
Threatening victims with data leaks on the dark web if ransoms are not paid.
Organizations should monitor for:
Fancy Bear targets include:
Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.
Since 2022, BianLian has executed numerous attacks on critical infrastructure in the U.S. and Australia.
The group has been particularly active in the healthcare sector, exploiting RDP vulnerabilities to gain access.
Limit RDP usage and enforce strong access controls.
Implement phishing-resistant multifactor authentication (MFA).
Regularly update and patch systems.
Use endpoint detection and response (EDR) tools to monitor for unusual activity.
No arrests or significant law enforcement actions against BianLian have been reported to date.
Notable developments include the U.S. indictment of GRU-affiliated officers in 2018. Despite these measures, Fancy Bear remains operational, emphasizing the challenges of deterring state-sponsored cyber actors.