YaLeak is a .NET data-exfiltration tool used by the China-linked APT31 espionage group. Reporting describes it as part of APT31 intrusions targeting Russia’s IT sector, especially contractors and integrators for government agencies, during activity observed from at least late 2022 and intensifying in 2024–2025. YaLeak uses Yandex Cloud to upload stolen information, fitting a broader APT31 tradecraft pattern of abusing legitimate cloud services for command-and-control and exfiltration in order to blend into normal traffic and hinder detection. The surrounding campaigns also involved spear-phishing, DLL sideloading, credential theft, local file discovery, and collection of sensitive data from sources such as browsers and Windows Sticky Notes. High-confidence attribution in the provided content links YaLeak to APT31, also known as Judgment Panda, TA412, and Violet Typhoon. The content does not provide specific YaLeak file hashes, domains, or other standalone IOCs beyond its use of Yandex Cloud for exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A data exfiltration tool used by APT31 that leverages Yandex Cloud to covertly transfer stolen data out of victim environments.
.NET exfiltration utility used to upload stolen information to Yandex Cloud.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.