🇷🇺BianLian
🇷🇺 BianLian is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 6 detection use cases to this actor across 11 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-08-15 to 2026-08-15.
crit 1
6Use cases
1Articles
11Techniques
0IOCs
Known aliases
BianLian
Top techniques
All other tracked techniques
Detection use cases (6)
SAP Commerce Cloud CVE-2026-58231: default OAuth client abuse against Data Hub Adapter SAP Commerce (Hybris) Java process spawning OS command shell — CVE-2026-58231 RCE payoff Infostealer — non-browser process accessing browser cookie/login DBs Asset exposure — vulnerability matches article CVE(s) Phishing-link click correlated to endpoint execution Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha)Threat-intel articles (1)
Tracked indicators
CVEs (1)
CVE-2026-58231