Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomwareUsed by 3 actors

Yanluowang

Yanluowang is a ransomware strain/group active from at least 2021 through late 2022. The content describes it as encrypting victim files and demanding payment, typically in cryptocurrency, while also stealing data and using double-extortion tactics by threatening to publish stolen information on leak sites if victims refused to pay. Reported ransom demands ranged from $300,000 to $15 million. Victims also reported coercive pressure tactics including harassing phone calls and distributed denial-of-service attacks. The group targeted large organizations and multiple U.S. sectors, including banks, telecommunications providers, engineering firms, and other corporate networks, with victims identified across states including Pennsylvania, California, Michigan, Illinois, Georgia, and Ohio. The operation relied in part on initial access brokers, notably Aleksei Olegovich Volkov (alias chubaka.kor), who between July 2021 and November 2022 identified and exploited vulnerabilities, breached corporate networks, and sold access to Yanluowang operators for flat fees and shares of ransom proceeds. Court reporting ties Yanluowang-enabled attacks to at least seven or eight U.S. companies and to more than $9 million in actual losses and over $24 million in intended losses. The content also notes that Symantec first identified the group in October 2021, that it was operational from around August 2021, and that it disbanded in late 2022 after its leak site was hacked and internal chat messages were exposed online. Some reporting cited in the content says the group was thought to be Chinese or was posing as Chinese hackers to obscure its members’ identities.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
yanluowang_ransomware_group

He assisted major cybercrime groups, including the Yanluowang ransomware group, charging up to $1,000 for access to business networks, as well as a percentage of the profits.

via itproitpro.com
UNC2447

Aleksei Olegovich Volkov ... served as the initial access broker for the Yanluowang ransomware group ... The victims ... said ... their data was stolen and encrypted by Yanluowang ransomware operators.

via cyberscoopcyberscoop.com
LAPSUS$

Aleksei Olegovich Volkov ... served as the initial access broker for the Yanluowang ransomware group ... The victims ... said ... their data was stolen and encrypted by Yanluowang ransomware operators.

via cyberscoopcyberscoop.com
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.

Yanluowang | Mallory