BianLian is a ransomware group known for multi-pronged extortion and hosting leak sites on TOR and I2P.
Analyst brief
BianLian is a ransomware group that started operations in late 2021. They employ multi-pronged extortion tactics, demanding payment both for a decryptor and to prevent the release of stolen data. The group maintains a public TOR-based blog to post victim identities and stolen data, and was notably one of the early adopters of an I2P mirror for their leak site. Defenders should focus on monitoring data leak sites on both TOR and I2P networks and be aware of their multi-faceted extortion approach.
bianlian
crime
BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog.