Yanluowang, also known as Dryxiphia, is a human-operated ransomware family first publicly identified in 2021 and used in targeted intrusions against enterprise organizations, with a notable concentration of victims in the United States financial sector as well as manufacturing, IT services, consultancy, and engineering. Reporting places its operational use from at least August 2021. Activity associated with Yanluowang has been linked to affiliates with experience in other ransomware ecosystems, including overlaps in tradecraft with Thieflock and infrastructure associations noted around UNC2447-related activity, although shared malware authorship with Thieflock has not been established.
Yanluowang is typically deployed late in the intrusion after hands-on-keyboard activity. Observed pre-encryption operations include Active Directory reconnaissance, remote system and service discovery, credential theft from browsers and password managers, remote access enablement, use of commercial remote administration software, and collection of data for exfiltration. BazarLoader and Cobalt Strike have been observed in related intrusion chains, and operators have used PowerShell, WMI, and network-scanning utilities to prepare victim environments for ransomware execution.
On execution, Yanluowang requires command-line parameters and appears intended for controlled deployment by an operator rather than indiscriminate self-spread. The malware encrypts files and appends a dedicated extension to affected data, then drops a ransom note. It impairs recovery and business continuity by terminating processes and stopping services associated with databases, backup platforms, email systems, business applications, security tools, and virtualization. Observed targets include SQL Server, Exchange, SharePoint, QuickBooks, Veeam, and Windows Defender, and the malware can stop hypervisor virtual machines through PowerShell. Technical analyses describe full encryption of smaller files and partial striped encryption of larger files, with cryptographic implementation weaknesses later enabling development of a public decryptor based on a known-plaintext attack.
Yanluowang has been associated with double-extortion operations in which attackers steal data before encryption and threaten publication or destruction of stolen information if victims refuse to pay. Its ransom messaging has also included coercive pressure tactics such as threats of repeated intrusions, distributed denial-of-service attacks, and direct contact with employees or business partners. Leaked internal communications attributed to the group suggested a structured operation with roles spanning development, negotiation, social engineering, and DDoS support, and indicated Russian-language communication among participants. Public leaks of internal chats and source code in late 2022 appear to have significantly disrupted the operation and may have contributed to its decline or cessation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Symantec has since associated UNC2447 with recent campaigns deploying Yanluowang Ransomware.
Yanluowang, the ransomware recently discovered by Symantec, is now being used by a threat actor that has been mounting targeted attacks against U.S. corporations since at least August 2021.
Yanluowang, the ransomware recently discovered by Symantec, is now being used by a threat actor that has been mounting targeted attacks against U.S. corporations since at least August 2021.
Yanluowang ransomware, also known as Dryxiphia, was first spotted in October 2021 by Symantec’s Threat Hunter Team. However, it has been operational since August 2021, when a threat actor used it to attack U.S. corporations.
He assisted major cybercrime groups, including the Yanluowang ransomware group, charging up to $1,000 for access to business networks, as well as a percentage of the profits.
Aleksei Olegovich Volkov ... served as the initial access broker for the Yanluowang ransomware group ... The victims ... said ... their data was stolen and encrypted by Yanluowang ransomware operators.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Uses Windows Management Instrumentation (WMI) to get a list of processes running on the remote machines listed in the .txt file
the attackers deploy Adfind... and SoftPerfect Network Scanner (netscan.exe), a publicly available tool used for discovery of hostnames and network services.
Uses Windows Management Instrumentation (WMI) to get a list of processes running on the remote machines listed in the .txt file Logs all the processes and remote machine names to processes.txt
In order to perform lateral movement and identify systems of interest, such as the victim’s Active Directory server, the attackers deploy Adfind, a free tool that can be used to query Active Directory
The criminals also threaten to repeat the attack “in a few weeks” and delete the victim’s data.
Encrypts files on the compromised computer and appends each file with the .yanluowang extension
The ransomware program has the functionality to terminate virtual machines, processes and services. | The ransomware program has the functionality to terminate virtual machines, processes and services. This is necessary to make files used by other programs available for encryption.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related content as a ransomware family used in targeted attacks against large enterprises.
Yanluowang is identified in the content as a ransomware family.
Ransomware family mentioned as appearing in CTI reporting tied to BitLaunch IP infrastructure.
Ransomware used against organizations globally. Attacks typically involve reconnaissance, credential harvesting, data exfiltration, then file encryption. It halts hypervisor virtual machines and running processes, encrypts files with the .yanluowang extension, drops a README.txt ransom note, and threatens DDoS attacks and later file deletion if victims do not comply.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.