
A new ransomware group, which operates under the name BianLian, emerged in late 2021 and has become increasingly active.
According to a research paper published by US cybersecurity firm Redacted, the threat actor already has twenty alleged victims across several industries, including insurance, medicine, law, and engineering. Most victim organizations have been based in Australia, North America, and the UK.
The research team believes the BianLian represents a group of individuals who are skilled in network penetration but relatively new to the extortion/ransomware business. It employs a special toolbox, which includes unofficial encryptors and encryption backdoors. Both are written in Go, a programming language that is becoming increasingly popular with ransomware threat actors. Go also powers the command-and-control (C&C) software that hackers employ.
Unsettlingly, the Redacted research team has discovered proof that BianLian is probably now trying to step up their game. The team noticed a seemingly alarming explosion in the rate at which BianLian was bringing new servers online beginning in August. This might signal that they’re prepared to speed up their operational pace.
BianLian typically targets SonicWall VPN equipment, servers that offer remote network access via services like Remote Desktop, the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), or SonicWall VPN devices to gain initial access to victim networks. The research paper claims that following exploitation, they released a web shell or a lightweight remote access program like ngrok as the follow-on payload. BianLian can take up to six weeks to begin the encryption process once it has entered the network.
They appeared to take steps to minimize observable events, using the living off the land (LOL) methodology to move laterally as BianLian would initially spread throughout a network, searching for the most valuable data to steal and identifying the most crucial machines to encrypt, said Redacted. Another indication of the high network penetration skills among BianLian members is their ability to adapt quickly. Redacted suggested using a multi-layered strategy to reduce the threat posed by ransomware actors like BianLian.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543