Yanluowang, also known as Dryxiphia, was a human-operated ransomware group active from at least 2021 and publicly identified in October 2021. The operation conducted targeted intrusions against enterprise organizations and used a structured division of labor that included development, negotiation, social engineering, penetration testing, distributed denial-of-service support, and initial access brokerage. Internal leak analysis indicated a multi-member team communicating primarily in Russian and suggested operational rules that avoided targeting certain former Soviet states. The group’s Chinese-themed branding has been assessed as deceptive rather than indicative of Chinese origin. Yanluowang targeted organizations globally, with especially well-documented activity against U.S. entities. Reported victim sectors include financial services, manufacturing, information technology services, consulting, engineering, telecommunications, and other corporate enterprises. The group relied on affiliates and external initial access brokers, including Aleksei Olegovich Volkov, who sold unauthorized access to victim networks later used in Yanluowang attacks against U.S. organizations. Observed tradecraft included reconnaissance, credential theft, lateral movement, remote access enablement, data exfiltration, and ransomware deployment. In some intrusions, operators used BazarLoader during early-stage activity, enabled remote desktop access, installed remote administration software, queried Active Directory, scanned internal networks, stole browser and password-manager credentials, captured screens, and exfiltrated victim data prior to encryption. The ransomware terminated processes and stopped virtualized infrastructure before encrypting files. Yanluowang used extortion pressure beyond encryption. The group threatened to leak stolen data, conduct repeated intrusions, delete victim data, launch distributed denial-of-service attacks, and contact employees or business partners. Victims were also reported to receive harassment as part of coercion. The operation maintained a leak site to publish stolen information from non-paying victims, making its activity consistent with double extortion and, in some cases, triple-extortion-style pressure through DDoS and third-party intimidation. Leak reporting tied Yanluowang to other ransomware ecosystems, including possible links to Thieflock, PayloadBIN, and former Conti personnel, though shared authorship with those operations was not established at high confidence. The group’s internal materials and source code were later exposed publicly, and its leak infrastructure reportedly went offline by late 2022, after which the operation appeared to cease or become inactive.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example from vendor reporting involving BitLaunch IP addresses.
Ransomware group whose leaked internal chats exposed its organization, operational security, recruitment, and TTPs. It conducted double-extortion style attacks involving reconnaissance, credential harvesting, data exfiltration, encryption, and threats of DDoS and file deletion.
Ransomware group whose attacks against U.S. companies were enabled by an initial access broker.
Ransomware group that purchased or benefited from initial access provided by Aleksei Volkov to compromise corporate networks in the United States and conduct ransomware and double-extortion attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.