Inactive ransomware operator
← All groupsBianLian
aka Hydra · 668 victims indexed · first seen 4 years ago · last activity 1 year ago
At a glance
- Status
- inactive
- Aliases
- Hydra
- First seen
- 4 years ago
- Last activity
- 1 year ago
- Onion sites
- 5 known endpoints
- Primary sector
- Healthcare · 65 hits
About
References
17 linksExternal sources curated by the MISP threat-intel community.
- blog.cyble.com/2022/08/18/bianlian-new-ransomware-variant-on-the-rise/
- blogs.blackberry.com/en/2022/10/bianlian-ransomware-encrypts-files-in-the-blink-of-an-eye
- cryptax.medium.com/android-bianlian-payload-61febabed00a
- cryptax.medium.com/bianlian-c-c-domain-name-4f226a29e221
- cryptax.medium.com/creating-a-safe-dummy-c-c-to-test-android-bots-ffa6e7a3dce5
- cryptax.medium.com/multidex-trick-to-unpack-android-bianlian-ed52eb791e56
- cryptax.medium.com/quick-look-into-a-new-sample-of-android-bianlian-bc5619efa726
- redacted.com/blog/bianlian-ransomware-gang-gives-it-a-go/
- rhisac.org/threat-intelligence/bianlian-ransomware-expanding-c2-infrastructure-and-operational-tempo/
- twitter.com/malwrhunterteam/status/1558548947584548865
- fortinet.com/blog/threat-research/new-wave-bianlian-malware
- threatfabric.com/blogs/bianlian_from_rags_to_riches_the_malware_dropper_that_had_a_dream.html
- virusbulletin.com/uploads/pdf/conference/vb2022/slides/VB2022-Hunting-the-Android-BianLian-botnet.pdf
- virusbulletin.com/uploads/pdf/conference/vb2022/papers/VB2022-Hunting-the-Android-BianLian-botnet.pdf
- youtube.com/watch?v=DPFcvSy4OZk
- fortinet.com/blog/threat-research/new-wave-bianlian-malware.html
- ransomlook.io/group/bianlian
Timeline
24 monthsTop countries
Top sectors
MITRE ATT&CK
4 techniques · 3 tacticsTactics
Recent victims
Loading…
Onion infrastructure
5 known- http://bianlianlbc5an4kgnay3opdemgcryg2kpfcbgczopmm3dnbz3uaunad.onion
- http://bianlianlbc5an4kgnay3opdemgcryg2kpfcbgczopmm3dnbz3uaunad.onion/companies/
- http://bianliaoxoeriowgqohcly4a6sbkpc3se2yvxgidxomxlpuhx5ehrpad.onion
- http://bianlivemqbawcco4cx4a672k2fip3guyxudzurfqvdszafam3ofqgqd.onion
- http://bianlivemqbawcco4cx4a672k2fip3guyxudzurfqvdszafam3ofqgqd.onion/companies/
Source
Updated 1 year agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
