Thieflock is a ransomware-as-a-service operation associated with the Fivehands group, also referred to as Canthroid. It has been linked through overlapping tradecraft to later ransomware intrusions involving Yanluowang affiliates, although available reporting does not establish shared malware authorship between Thieflock and Yanluowang. The most plausible connection identified is affiliate overlap rather than common development.
Thieflock activity is associated with enterprise-targeted intrusions that include network discovery, credential theft, remote access enablement, and data theft prior to ransomware deployment. Reported overlapping tooling and behavior include use of browser password recovery utilities, Active Directory enumeration, network scanning, and collection of credentials from browsers and password managers. The broader intrusion pattern tied to affiliated operators includes use of PowerShell-delivered tooling, remote administration software, and post-compromise reconnaissance to identify systems of interest and expand access within victim environments.
The operation has been associated with attacks against U.S. organizations, particularly in the financial sector, with additional victims in manufacturing, IT services, consultancy, and engineering. Thieflock is best understood as part of the financially motivated big-game hunting ransomware ecosystem in which affiliates conduct hands-on-keyboard intrusions, steal sensitive data, and deploy encryption for extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
There is a tentative link between these Yanluowang attacks and older attacks involving Thieflock, ransomware-as-a-service developed by the Canthroid (aka Fivehands) group.
There is a tentative link between these Yanluowang attacks and older attacks involving Thieflock, ransomware-as-a-service developed by the Canthroid (aka Fivehands) group.
Based on the tactics, techniques, and procedures (TTPs) used in these attacks, this Yanluowang affiliate was linked to the Thieflock ransomware operation developed by the Fivehands group.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware with similar TTPs to early Yanluowang attacks, suggesting a possible affiliate or operational link.
Named ransomware operation linked by TTP overlap to a Yanluowang affiliate and attributed in the article to the Fivehands group.
Ransomware operation linked by researchers through overlapping TTPs with recent Yanluowang attacks; described as developed by the Fivehands group.
A ransomware-as-a-service family linked here through overlapping TTPs with Yanluowang attacks; the article suggests the operators may be former Thieflock affiliates rather than sharing malware authorship.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.