Credential Theft
- GrabChrome
- GrabFF
- KeeThief
- Mimikatz
- NirSoft WebBrowserPassView
Yanluowang is a human-operated ransomware family active from 2021 through late 2022 and associated with targeted intrusions against organizations in the United States and elsewhere.
Profile source: Mallory opens in a new tabYanluowang
Yanluowang is a human-operated ransomware family active from 2021 through late 2022 and associated with targeted intrusions against organizations in the United States and elsewhere. It is known for encrypting victim systems, stealing data prior to encryption, and using double-extortion to pressure payment by threatening public disclosure of stolen information. Reported victim sectors include banking, telecommunications, engineering, and other corporate environments.
Operations linked to Yanluowang relied on an affiliate-style ecosystem that included initial access brokers who identified and exploited vulnerabilities in corporate networks, then sold or shared that access with ransomware operators. After gaining entry, operators conducted follow-on intrusion activity including lateral movement, deployment of ransomware, and extortion. In some cases, coercive pressure reportedly extended beyond encryption and leak-site threats to harassment such as phone calls and distributed denial-of-service activity against victims.
The group behind Yanluowang has been assessed as attempting to present a false Chinese persona, despite reporting that its operators were likely not Chinese. The ransomware operation was publicly identified in 2021 and later disbanded in late 2022 after compromise of its leak infrastructure and exposure of internal communications. A weakness in its encryption implementation was reported to have enabled development of a free decryption tool for some victims.
Reported operators
He assisted major cybercrime groups, including the Yanluowang ransomware group, charging up to $1,000 for access to business networks, as well as a percentage of the profits.
Aleksei Olegovich Volkov ... served as the initial access broker for the Yanluowang ransomware group ... The victims ... said ... their data was stolen and encrypted by Yanluowang ransomware operators.
Aleksei Olegovich Volkov ... served as the initial access broker for the Yanluowang ransomware group ... The victims ... said ... their data was stolen and encrypted by Yanluowang ransomware operators.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.