Validin will be at Black Hat 2026, Booth #6200 — schedule time to meet with us for an enterprise demo or an online meeting

BianLian

Aliases: Argonauts • BianLian is a ransomware group, now operating as Argonauts, that targets healthcare and manufacturing organizations, employing both double extortion and extortion-only tactics.
Profile
Malware
Category
Threat Actor Group
Threat Type
Unknown
Country
bianlian
Profile Key
The profile key is a unique identifier for this threat actor. It can be used to query the Validin APIs as the threat_key for information about this threat actor.
Last Updated
Summary
Indicator Activity
Loading activity...
No indicators recorded yet.
Description

BianLian is a ransomware group that has been active since at least 2022, primarily targeting the healthcare and manufacturing sectors in the United States and Europe. The group is known for its use of a double extortion scheme, where they encrypt victims' data and threaten to publish it if a ransom is not paid. However, BianLian has recently shifted to an extortion-only model, focusing on data theft and extortion without encryption. The group shares a customized tool with the Makop ransomware group, suggesting a potential connection between the two. Bianlian is now operating as Argonauts.

Aliases (1)
Argonauts
Alias
Targets (3)
Windows
Target
Healthcare
Target
Manufacturing
Target
External Sources