Yanluowang, also known as Dryxiphia, is a financially motivated ransomware and extortion operation active from at least August 2021 and first publicly identified in October 2021. It conducted human-operated attacks against enterprise networks worldwide, with documented targeting concentrated in the United States. Victims included financial institutions, manufacturing companies, IT service providers, consultancies, engineering firms, and telecommunications providers. Its ecosystem included Russian-speaking participants, ransomware affiliates, and initial access brokers. Yanluowang intrusions involved reconnaissance, credential theft, lateral movement, data exfiltration, and file encryption. An observed affiliate used BazarLoader during reconnaissance and lateral movement, enabled RDP access, and installed ConnectWise for remote access. Discovery tools included AdFind and SoftPerfect Network Scanner. Credential-stealing tools targeted browser passwords and KeePass master keys, while Filegrab supported data exfiltration. Yanluowang operators also used Veeamp to extract and decrypt credentials stored in the SQL database supporting Veeam backup management software. Before encrypting files, the ransomware stopped hypervisor virtual machines and terminated running processes. The operation combined encryption and stolen-data leak threats with additional pressure tactics, including DDoS attacks and harassing telephone calls. Operators published stolen information on leak sites and threatened to contact employees and business partners, repeat intrusions, and delete victim data. Russian initial access broker Aleksei Olegovich Volkov supplied compromised network access and conducted DDoS attacks in support of Yanluowang between July 2021 and November 2022; he subsequently received an 81-month U.S. prison sentence. Kaspersky identified an encryption weakness that enabled known-plaintext recovery and added Yanluowang support to RannohDecryptor. In late 2022, a compromise exposed internal communications, infrastructure information, and ransomware source code, disrupting the operation and leading to its disbandment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example from vendor reporting involving BitLaunch IP addresses.
Ransomware group whose leaked internal chats exposed its organization, operational security, recruitment, and TTPs. It conducted double-extortion style attacks involving reconnaissance, credential harvesting, data exfiltration, encryption, and threats of DDoS and file deletion.
Ransomware group whose attacks against U.S. companies were enabled by an initial access broker.
Ransomware group that purchased or benefited from initial access provided by Aleksei Volkov to compromise corporate networks in the United States and conduct ransomware and double-extortion attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.