Threat Actor Profile

BianLian

BianLian is a ransomware and data extortion group, first observed in June 2022. Likely based in Russia, the group targets critical infrastructure sectors in the U.S. and Australia. Known for their exfiltration-based extortion tactics, BianLian has shifted away from encrypting systems, focusing instead on data theft and extortion.

Threat Actor Profile

BianLian

Fancy Bear TTPs

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Country of Origin

BianLian is likely based in Russia, with evidence pointing to Russia-based affiliates. However, no definitive confirmation exists.

Members

The exact size and composition of the group are unknown. It is assumed to be a small, organized team with specialized roles in ransomware development, deployment, and extortion.

Leadership

The leadership of BianLian remains unknown. No aliases or specific individuals have been publicly identified.

Tactics

BianLian primarily focuses on exfiltration-based extortion, targeting sensitive data to pressure victims into paying ransoms.

Techniques

  • Gaining access via compromised Remote Desktop Protocol (RDP) credentials.

  • Using open-source tools like PowerShell and command-line scripting for discovery and credential harvesting.

  • Exfiltrating data via FTP, Rclone, or Mega.

Procedures

  • Deploying custom backdoors written in Go for persistence.

  • Disabling antivirus tools and tamper protection.

  • Threatening victims with data leaks on the dark web if ransoms are not paid.

Want to shut down threats before they start?

Indicators of Compromise (IOCs)

Organizations should monitor for:

  • Known Fancy Bear malware signatures (e.g., XAgent, ADVSTORESHELL).
  • Suspicious domains mimicking government or defense entities.
  • Zero-day exploits in applications like Microsoft Windows and Adobe Flash.
  • Abnormal network traffic patterns indicating command-and-control communications.

Key Victims

Fancy Bear targets include:

  • Governments (United States, Germany, France, Ukraine, and others).
  • Military Organizations (focus on NATO-aligned entities).
  • Media Outlets and Journalists (especially those covering Kremlin-related topics).
  • Critical Infrastructure (energy, aerospace, and defense).
  • International Sporting Organizations (e.g., WADA).
  • Political Groups (e.g., the Democratic National Committee).

Notable Cyber Attacks

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Notable Cyberattacks
  • Since 2022, BianLian has executed numerous attacks on critical infrastructure in the U.S. and Australia.

  • The group has been particularly active in the healthcare sector, exploiting RDP vulnerabilities to gain access.

Glitch effectGlitch effect

How to Defend Against BianLian

1

Limit RDP usage and enforce strong access controls.

2

Implement phishing-resistant multifactor authentication (MFA).

3

Regularly update and patch systems.

4

Use endpoint detection and response (EDR) tools to monitor for unusual activity.

Law Enforcement & Arrests

No arrests or significant law enforcement actions against BianLian have been reported to date.

References

Related Threat Actor Profiles

Notable developments include the U.S. indictment of GRU-affiliated officers in 2018. Despite these measures, Fancy Bear remains operational, emphasizing the challenges of deterring state-sponsored cyber actors.

Detect, Respond, Protect

See how the global Huntress SOC can augment your team
with 24/7 coverage and unmatched human expertise.
Start your free trial today.

Try Huntress for Free