Yanluowang is a ransomware family active from at least 2021 through late 2022 that targeted organizations in the United States and elsewhere, including banks, telecommunications providers, engineering firms, and other enterprises. It is associated with double-extortion operations in which operators encrypted victim data, stole information prior to encryption, and threatened public disclosure on leak sites if payment was not made. Reported coercive tactics also included harassing phone calls and distributed denial-of-service pressure against victims during negotiations. Ransom demands ranged from hundreds of thousands to many millions of dollars in cryptocurrency.
The operation relied on an affiliate-style division of labor that included initial access brokers who identified and exploited vulnerabilities in corporate networks, sold or shared unauthorized access with ransomware operators, and in some cases received a percentage of ransom proceeds. U.S. court cases tied Aleksei Volkov to providing access for multiple Yanluowang intrusions between July 2021 and November 2022. Public reporting also links the group to attempted extortion against Cisco. Researchers first publicly identified the family in 2021, and later reporting indicated the operators used a false Chinese persona to obscure their identities. The group is generally assessed to have disbanded in late 2022 after its leak site was compromised and internal chats were exposed. A weakness in the malware’s encryption scheme enabled release of a free decryptor in 2022.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
He assisted major cybercrime groups, including the Yanluowang ransomware group, charging up to $1,000 for access to business networks, as well as a percentage of the profits.
Aleksei Olegovich Volkov ... served as the initial access broker for the Yanluowang ransomware group ... The victims ... said ... their data was stolen and encrypted by Yanluowang ransomware operators.
Aleksei Olegovich Volkov ... served as the initial access broker for the Yanluowang ransomware group ... The victims ... said ... their data was stolen and encrypted by Yanluowang ransomware operators.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family mentioned as appearing in CTI reporting tied to BitLaunch IP infrastructure.
Ransomware used by affiliates who purchased initial access to compromise corporate networks, encrypt sensitive business data, and conduct double-extortion by threatening to leak stolen data.
Ransomware used in attacks for which Volkov acted as an initial access broker.
Ransomware used by a criminal gang to breach companies and cause significant financial damage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.