Skip to content

Malware

BianLian

BianLian is a GoLang-based ransomware that continues to breach several industries and demand large ransom amounts.

BianLian is a Windows malware family.

Background

BianLian is a ransomware written in GoLang that has repeatedly compromised organizations across multiple sectors while demanding sizeable ransoms. Its operators rely on double extortion, exfiltrating a victim's files and publishing them online if payment is not made in time. Initial access is typically obtained through valid Remote Desktop Protocol (RDP) credentials, after which the actors lean on open-source tooling and command-line scripts for discovery and credential theft, exfiltrating data over File Transfer Protocol (FTP), Rclone, or Mega. Although the group originally encrypted systems after stealing data, around January 2023 it pivoted to an extortion model focused mainly on data theft. To compromise a host quickly, the ransomware leverages goroutines and encrypts files in chunks, appending its own extension to every encrypted file.


Source: Malpedia (Fraunhofer FKIE).