Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ BianLian

🇷🇺BianLian

🇷🇺 BianLian is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 6 detection use cases to this actor across 11 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-08-15 to 2026-08-15.

crit 1
View full actor card → All threat actors
6Use cases
1Articles
11Techniques
0IOCs

Known aliases

BianLian

Top techniques

All other tracked techniques

Detection use cases (6)

SAP Commerce Cloud CVE-2026-58231: default OAuth client abuse against Data Hub Adapter Bespoke SAP Commerce (Hybris) Java process spawning OS command shell — CVE-2026-58231 RCE payoff Bespoke Infostealer — non-browser process accessing browser cookie/login DBs Internal Asset exposure — vulnerability matches article CVE(s) Internal Phishing-link click correlated to endpoint execution Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal

Threat-intel articles (1)

Tracked indicators

CVEs (1)

CVE-2026-58231