public mosaic llc support@publicmosaic.com
malware family

BianLian

5 addresses convicted as BianLian command-and-control servers — 5 still listed, 0 archived. Observed from 2026-09-01.

TLP:CLEAR
addresses 5 5 still listed
observations 7 address and port pairs
networks 4 distinct ASNs
first seen 2026-09-01 oldest observation

Detection packs

Rules for the 5 still-listed addresses on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.

About

BianLian is a Go-based backdoor named for the extortion group that deploys it. The group moved from encrypting victims to pure data-theft extortion in 2023; its implants beacon to operator-run servers, which are what this corpus lists.

Ports

:84433:4432:801:84441

Addresses

Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.