Yanluowang is a ransomware extortion group active from at least 2021 through late 2022 and known for highly targeted intrusions against organizations in the United States and elsewhere. The group operated as part of the broader ransomware ecosystem, relying in part on initial access brokers to obtain footholds in victim networks before conducting lateral movement, data theft, encryption, and extortion. Public reporting and court records tie Russian cybercriminal Aleksei Olegovich Volkov, also known as chubaka.kor, to the group as an initial access broker who sold or provided access used in multiple Yanluowang attacks between July 2021 and November 2022. Yanluowang used double-extortion tactics, combining file encryption with theft of sensitive data and threats to publish stolen information on a leak site if victims refused to pay. Victims were also pressured through additional coercive measures including distributed denial-of-service activity and harassing communications. Reported targeting included U.S. businesses across sectors such as banking, telecommunications, and engineering. Ransom demands ranged from hundreds of thousands to many millions of dollars, and attacks attributed to access sold to the group caused substantial financial and operational harm. Despite its Chinese-sounding name, Yanluowang has been assessed by researchers as a criminal group likely masquerading as Chinese actors rather than being a confirmed Chinese state-linked operation. The group has also been associated with use of tooling and tradecraft seen in other Russian-language ransomware ecosystems. Similar Veeam-focused credential theft activity has been noted in connection with Yanluowang operations. The group maintained a public leak site to shame victims and increase payment pressure. Yanluowang is also referred to as Yanluowang ransomware group. The operation appears to have disbanded in late 2022 after its leak site was compromised and internal chat messages were exposed, an event that significantly disrupted the group’s operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group whose attacks against U.S. companies were enabled by an initial access broker.
Ransomware group that purchased or benefited from initial access provided by Aleksei Volkov to compromise corporate networks in the United States and conduct ransomware and double-extortion attacks.
A ransomware group referenced in connection with attacks enabled by an initial access broker.
Ransomware gang involved in breaching U.S. companies and causing millions of dollars in damage.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.