Skip to content

bianlian

Inactive

25 tracked victims · First seen Jul 14, 2022 · Last seen Mar 31, 2025

About

Aggregated threat-intel description

BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog.

Sectors: Business Services, Healthcare, Financial · Countries: US, CA, IN

Recent victims

View all →
VictimSectorCountryPostedStatus
CMC Technology GroupTechnologyVNMar 31, 2025
Meridian SeniorHealthcareUSMar 31, 2025
Saunders and SaundersNot FoundMar 31, 2025
Sonrisas Dental HealthHealthcareUSMar 31, 2025
Goshen Medical CenterHealthcareUSMar 22, 2025
AllworxTelecommunicationUSMar 7, 2025
Island RealtyNot FoundUSMar 7, 2025
Minnesota OrthodonticsHealthcareUSMar 7, 2025
Keystone Pacific Property Management LLCBusiness ServicesUSMar 4, 2025
Mosley Glick O’Brien, Inc.Not FoundUSMar 4, 2025
Legal Aid Society of Salt LakePublic SectorUSMar 4, 2025
Ewald ConsultingBusiness ServicesUSMar 4, 2025
Alabama Ophthalmology AssociatesHealthcareUSFeb 19, 2025
Aspire Rural Health SystemHealthcareUSFeb 13, 2025
Nash Brothers ConstructionConstructionUSFeb 13, 2025
Nippon Steel USAManufacturingUSFeb 13, 2025
Financial Services of America, Inc.Financial ServicesUSFeb 13, 2025
Layfield & Borel CPA's L.L.CFinancial ServicesUSFeb 13, 2025
Dain, Torpy, Le Ray, Wiest & Garner, P.C.Business ServicesUSFeb 13, 2025
D-7 RoofingConstructionUSFeb 10, 2025
Recievership SpecialistsBusiness ServicesUSFeb 10, 2025
Dash BusinessNot FoundFeb 5, 2025
Hall ChadwickFinancial ServicesAUFeb 5, 2025
NESCTC Security ServicesBusiness ServicesUSFeb 5, 2025
C & R Molds IncManufacturingUSFeb 4, 2025

All ransomware groups · Dark web intelligence