Credential Theft
- GrabChrome
- GrabFF
- KeeThief
- Mimikatz
- NirSoft WebBrowserPassView
Yanluowang, also known as Dryxiphia, is a human-operated ransomware family first publicly identified in 2021 and used in targeted intrusions against enterprise organizations, with a notable concentration of victims in the United States financial sector as well as manufacturing, IT services, consultancy, and engineering.
Profile source: Mallory opens in a new tabYanluowang
Yanluowang, also known as Dryxiphia, is a human-operated ransomware family first publicly identified in 2021 and used in targeted intrusions against enterprise organizations, with a notable concentration of victims in the United States financial sector as well as manufacturing, IT services, consultancy, and engineering. Reporting places its operational use from at least August 2021. Activity associated with Yanluowang has been linked to affiliates with experience in other ransomware ecosystems, including overlaps in tradecraft with Thieflock and infrastructure associations noted around UNC2447-related activity, although shared malware authorship with Thieflock has not been established.
Yanluowang is typically deployed late in the intrusion after hands-on-keyboard activity. Observed pre-encryption operations include Active Directory reconnaissance, remote system and service discovery, credential theft from browsers and password managers, remote access enablement, use of commercial remote administration software, and collection of data for exfiltration. BazarLoader and Cobalt Strike have been observed in related intrusion chains, and operators have used PowerShell, WMI, and network-scanning utilities to prepare victim environments for ransomware execution.
On execution, Yanluowang requires command-line parameters and appears intended for controlled deployment by an operator rather than indiscriminate self-spread. The malware encrypts files and appends a dedicated extension to affected data, then drops a ransom note. It impairs recovery and business continuity by terminating processes and stopping services associated with databases, backup platforms, email systems, business applications, security tools, and virtualization. Observed targets include SQL Server, Exchange, SharePoint, QuickBooks, Veeam, and Windows Defender, and the malware can stop hypervisor virtual machines through PowerShell. Technical analyses describe full encryption of smaller files and partial striped encryption of larger files, with cryptographic implementation weaknesses later enabling development of a public decryptor based on a known-plaintext attack.
Yanluowang has been associated with double-extortion operations in which attackers steal data before encryption and threaten publication or destruction of stolen information if victims refuse to pay. Its ransom messaging has also included coercive pressure tactics such as threats of repeated intrusions, distributed denial-of-service attacks, and direct contact with employees or business partners. Leaked internal communications attributed to the group suggested a structured operation with roles spanning development, negotiation, social engineering, and DDoS support, and indicated Russian-language communication among participants. Public leaks of internal chats and source code in late 2022 appear to have significantly disrupted the operation and may have contributed to its decline or cessation.
Reported operators
Symantec has since associated UNC2447 with recent campaigns deploying Yanluowang Ransomware.
Yanluowang, the ransomware recently discovered by Symantec, is now being used by a threat actor that has been mounting targeted attacks against U.S. corporations since at least August 2021.
Yanluowang, the ransomware recently discovered by Symantec, is now being used by a threat actor that has been mounting targeted attacks against U.S. corporations since at least August 2021.
Yanluowang ransomware, also known as Dryxiphia, was first spotted in October 2021 by Symantec’s Threat Hunter Team. However, it has been operational since August 2021, when a threat actor used it to attack U.S. corporations.
He assisted major cybercrime groups, including the Yanluowang ransomware group, charging up to $1,000 for access to business networks, as well as a percentage of the profits.
Aleksei Olegovich Volkov ... served as the initial access broker for the Yanluowang ransomware group ... The victims ... said ... their data was stolen and encrypted by Yanluowang ransomware operators.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.