Skip to content

Yanluowang

Yanluowang, also known as Dryxiphia, is a human-operated ransomware family first publicly identified in 2021 and used in targeted intrusions against enterprise organizations, with a notable concentration of victims in the United States financial sector as well as manufacturing, IT services, consultancy, and engineering.

Profile source: Mallory opens in a new tab

Yanluowang

Family profile

Yanluowang, also known as Dryxiphia, is a human-operated ransomware family first publicly identified in 2021 and used in targeted intrusions against enterprise organizations, with a notable concentration of victims in the United States financial sector as well as manufacturing, IT services, consultancy, and engineering. Reporting places its operational use from at least August 2021. Activity associated with Yanluowang has been linked to affiliates with experience in other ransomware ecosystems, including overlaps in tradecraft with Thieflock and infrastructure associations noted around UNC2447-related activity, although shared malware authorship with Thieflock has not been established.

Yanluowang is typically deployed late in the intrusion after hands-on-keyboard activity. Observed pre-encryption operations include Active Directory reconnaissance, remote system and service discovery, credential theft from browsers and password managers, remote access enablement, use of commercial remote administration software, and collection of data for exfiltration. BazarLoader and Cobalt Strike have been observed in related intrusion chains, and operators have used PowerShell, WMI, and network-scanning utilities to prepare victim environments for ransomware execution.

On execution, Yanluowang requires command-line parameters and appears intended for controlled deployment by an operator rather than indiscriminate self-spread. The malware encrypts files and appends a dedicated extension to affected data, then drops a ransom note. It impairs recovery and business continuity by terminating processes and stopping services associated with databases, backup platforms, email systems, business applications, security tools, and virtualization. Observed targets include SQL Server, Exchange, SharePoint, QuickBooks, Veeam, and Windows Defender, and the malware can stop hypervisor virtual machines through PowerShell. Technical analyses describe full encryption of smaller files and partial striped encryption of larger files, with cryptographic implementation weaknesses later enabling development of a public decryptor based on a known-plaintext attack.

Yanluowang has been associated with double-extortion operations in which attackers steal data before encryption and threaten publication or destruction of stolen information if victims refuse to pay. Its ransom messaging has also included coercive pressure tactics such as threats of repeated intrusions, distributed denial-of-service attacks, and direct contact with employees or business partners. Leaked internal communications attributed to the group suggested a structured operation with roles spanning development, negotiation, social engineering, and DDoS support, and indicated Russian-language communication among participants. Public leaks of internal chats and source code in late 2022 appear to have significantly disrupted the operation and may have contributed to its decline or cessation.

Capabilities

  • Credential Theft
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Post Exploitation
  • Reconnaissance

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Credential Theft

  • GrabChrome
  • GrabFF
  • KeeThief
  • Mimikatz
  • NirSoft WebBrowserPassView

Discovery Enum

  • AdFind
  • Cent Browser
  • S3 Browser
  • SoftPerfect NetScan

LOLBAS

  • NTDS Utility (ntdsutil)
  • PsExec
  • Windows Event Utility (wevtutil)

Networking

  • Chisel

Offsec

  • Cobalt Strike
  • Impacket

RMM Tools

  • LogMeIn
  • ScreenConnect
  • TeamViewer

Reported operators

Threat actors

6 named in public reporting
UNC2447

Symantec has since associated UNC2447 with recent campaigns deploying Yanluowang Ransomware.

Canthroid

Yanluowang, the ransomware recently discovered by Symantec, is now being used by a threat actor that has been mounting targeted attacks against U.S. corporations since at least August 2021.

FIVEHANDS

Yanluowang, the ransomware recently discovered by Symantec, is now being used by a threat actor that has been mounting targeted attacks against U.S. corporations since at least August 2021.

INDRIK SPIDER

Yanluowang ransomware, also known as Dryxiphia, was first spotted in October 2021 by Symantec’s Threat Hunter Team. However, it has been operational since August 2021, when a threat actor used it to attack U.S. corporations.

Yanluowang

He assisted major cybercrime groups, including the Yanluowang ransomware group, charging up to $1,000 for access to business networks, as well as a percentage of the profits.

LAPSUS$

Aleksei Olegovich Volkov ... served as the initial access broker for the Yanluowang ransomware group ... The victims ... said ... their data was stolen and encrypted by Yanluowang ransomware operators.

MITRE ATT&CK

Yanluowang in ATT&CK

24 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.