Yanluowang, also known as Dryxiphia, is a Windows ransomware family used in targeted, human-operated attacks against enterprise networks. First identified in October 2021, it was deployed in attacks against U.S. corporations from at least August 2021. Observed targets include financial services, manufacturing, IT services, consultancy, and engineering organizations, with victims in the United States, Brazil, Turkey, and other countries. Campaigns deploying Yanluowang have been associated with UNC2447 and have used access supplied by initial access brokers.
The ransomware accepts command-line parameters specifying an encryption target and, in analyzed variants, an execution password. Before encryption, it stops Hyper-V virtual machines and terminates processes and services associated with databases, backup products, email systems, business applications, and security software, including Windows Defender. Some samples carried valid digital signatures. Analyzed variants encrypt files with the Sosemanuk stream cipher and protect the encryption key with RSA-1024. Files up to 3 GB are fully encrypted, while larger files are encrypted intermittently in 5 MB stripes separated by 200 MB. A cryptographic weakness enables known-plaintext recovery using Kaspersky's RannohDecryptor when suitable original and encrypted file pairs are available.
Yanluowang intrusions have involved BazarLoader-assisted reconnaissance, Active Directory discovery with AdFind, network scanning, RDP enablement, and ConnectWise remote access. Operators have used separate tools to steal browser and password-manager credentials, extract Veeam credentials, capture screens, and exfiltrate files before deploying ransomware. These activities support double extortion rather than representing built-in capabilities of the encryptor. Ransom notes demand payment and threaten further intrusions, data deletion, DDoS attacks, and contact with employees or business partners. These threats do not establish that the ransomware itself implements DDoS or data-wiping functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Possible Ransomware Affiliations ... Monti Ransomware ... Yanluowang Ransomware
Symantec has since associated UNC2447 with recent campaigns deploying Yanluowang Ransomware.
Yanluowang, the ransomware recently discovered by Symantec, is now being used by a threat actor that has been mounting targeted attacks against U.S. corporations since at least August 2021.
Yanluowang, the ransomware recently discovered by Symantec, is now being used by a threat actor that has been mounting targeted attacks against U.S. corporations since at least August 2021.
Yanluowang ransomware, also known as Dryxiphia, was first spotted in October 2021 by Symantec’s Threat Hunter Team. However, it has been operational since August 2021, when a threat actor used it to attack U.S. corporations.
Aleksei Olegovich Volkov ... served as the initial access broker for the Yanluowang ransomware group ... The victims ... said ... their data was stolen and encrypted by Yanluowang ransomware operators.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Uses Windows Management Instrumentation (WMI) to get a list of processes running on the remote machines listed in the .txt file
the attackers deploy Adfind... and SoftPerfect Network Scanner (netscan.exe), a publicly available tool used for discovery of hostnames and network services.
Uses Windows Management Instrumentation (WMI) to get a list of processes running on the remote machines listed in the .txt file Logs all the processes and remote machine names to processes.txt
In order to perform lateral movement and identify systems of interest, such as the victim’s Active Directory server, the attackers deploy Adfind, a free tool that can be used to query Active Directory
The criminals also threaten to repeat the attack “in a few weeks” and delete the victim’s data.
Encrypts files on the compromised computer and appends each file with the .yanluowang extension
The ransomware program has the functionality to terminate virtual machines, processes and services. | The ransomware program has the functionality to terminate virtual machines, processes and services. This is necessary to make files used by other programs available for encryption.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related content as a ransomware family used in targeted attacks against large enterprises.
Yanluowang is identified in the content as a ransomware family.
Ransomware family mentioned as appearing in CTI reporting tied to BitLaunch IP infrastructure.
Ransomware used against organizations globally. Attacks typically involve reconnaissance, credential harvesting, data exfiltration, then file encryption. It halts hypervisor virtual machines and running processes, encrypts files with the .yanluowang extension, drops a README.txt ransom note, and threatens DDoS attacks and later file deletion if victims do not comply.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.