The Yanluowang ransomware operation targeted U.S. organizations, with a particular focus on the financial sector, using BazarLoader during reconnaissance and initial compromise before expanding access through enabled RDP and remote-management tools such as ConnectWise. Intrusions documented by Symantec and linked reporting showed the actors conducting network discovery with tools including AdFind and SoftPerfect Network Scanner, while also deploying credential-theft and data-exfiltration utilities ahead of ransomware deployment. U.S. government reporting on FiveHands provides additional context for tradecraft overlaps that researchers said may indicate ties to earlier ransomware-as-a-service activity, though direct shared authorship was not confirmed.
A later leak of Yanluowang internal chats, infrastructure details, and source code exposed a more structured criminal enterprise, with separate roles for development, negotiations, social engineering, pentesting, and DDoS operations. The leaked material suggested links to Thieflock, PayloadBIN, Conti, and references to REvil, while indicating the group avoided targets in former Soviet states and took steps to discuss operational security and money laundering. Researchers said the leak appears to have disrupted the gang’s operations, with onion sites reportedly going offline, but warned that publication of the ransomware source code and builder could aid both defenders and future threat actors seeking to reuse the tooling.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Darktrace published an analysis of leaked internal chats, infrastructure details, and source code, identifying at least eighteen people involved and describing a structured division of labor across development, negotiations, social engineering, pentesting, and DDoS roles. The analysis also highlighted possible links to PayloadBIN, Conti, and Thieflock-related ecosystems.
Kaspersky reported a cryptographic weakness in Yanluowang's encryption scheme that allows file recovery via a known-plaintext attack. The company added free Yanluowang decryption support to its Rannoh tool to help victims recover encrypted files.
Trend Micro analyzed newly observed Yanluowang ransomware samples and reported that the binaries were code-signed with a valid digital signature at the time of analysis. The report also documented the malware's use of command-line execution, termination of database, backup, email, and administrative processes and services, and attempts to stop virtual machines to increase operational impact on victims.
Symantec reported that Yanluowang attacks were continuing against higher-profile U.S. targets and assessed that the actor appeared to be an experienced ransomware affiliate. The company said the activity may be tied to a former Thieflock/FiveHands affiliate, though the connection remained tentative and without proof of shared authorship.
On 31 October, the @yanluowangleaks account shared Yanluowang Matrix chat leaks, server leaks, the builder, and decryption source. The leak included six files containing internal conversations between group members.
Symantec's Threat Hunter Team first identified Yanluowang in October 2021, marking the firm's initial observation of the ransomware operation.
The group was described as operational since August 2021, and a threat actor used Yanluowang to attack U.S. corporations that month. Those attacks reportedly shared similar tactics, techniques, and procedures with Thieflock/FiveHands activity.
CISA published analysis report AR21-126A on FiveHands ransomware, documenting the malware family later referenced in assessments of possible links to Yanluowang activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
de.darktrace.com
Open sourcesecurelist.com
Open sourcetrendmicro.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourcebleepingcomputer.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceus-cert.cisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.