Ransomware Group intelligence
Yanluowang
InactiveTrack Yanluowang with 6 published victims and 1 known leak locations in a single intelligence view.
Overview
Yanluowang is tracked by Breach House as a ransomware group with 6 published victims.
The group is tracked across multiple victim records in the Breach House dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 3h ago | jukswsxbh3jsxuddvidrjdvwuohtsy4kxg2axbppiyclomt2qciyfoad.onion |
Top Activity Sectors (4)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Yanluowang, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: low. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: yanluowang executes malicious commands via PowerShell scripts to propagate and stage ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: yanluowang leverages native Windows API calls to bypass detection while performing file encryption and system manipulation.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: yanluowang establishes persistence by injecting malicious code into Windows Registry Run Keys to execute ransomware automatically on system startup.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: yanluowang disables antivirus tools and security software using registry modifications and process manipulation to ensure undetected encryption.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: yanluowang encodes victim files with symmetric encryption keys before deployment to ensure data integrity checks fail and decryption is impossible.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: yanluowang deletes Volume Shadow Copies and backup directories via command-line tools to prevent data recovery and increase victim pressure.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1486 Data Encrypted for Impact Impact
What they do: yanluowang encrypts victim files using custom ransomware binaries, targeting documents and images to maximize disruption and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: yanluowang halts system recovery processes by terminating critical services and modifying system configurations to lock victims out.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (18)
▼Software Yanluowang has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Discovery & enumeration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
yanluowang.txt
Hi, since you are reading this it means you have been hacked. In addition to encrypting all your systems, deleting backups, we also downloaded 2 terabytes of confidential information. Here's what you shouldn't do: 1) Contact the police, fbi or other authorities before the end of our deal 2) Contact the recovery company so that they would conduct dialogues with us. (This can slow down the recovery, and generally put our communication to naught) 3) Do not try to decrypt the files yourself, as well as do not change the file extension yourself !!! This can lead to the impossibility of their decryption. 4) Keep us for fools) We will also stop any communication with you, and continue DDoS, calls to employees and business partners. In a few weeks, we will simply repeat our attack and delete all your data from your networks, WHICH WILL LEAD TO THEIR UNAVAILABILITY! Here's what you should do right after reading it: 1) If you are an ordinary employee, send our message to the CEO of the company, as well as to the IT department 2) If you are a CEO, or a specialist in the IT department, or another person who has weight in the company, you should contact us within 24 hours by email. We are ready to confirm all our intentions regarding DDOS, calls, and deletion of the date at your first request. As a guarantee that we can decrypt the files, we suggest that you send several files for free decryption. Mails to contact us: 1)cang.leen@mailfence\.com 2)yan.laowang@mailfence\.com
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (6)
Search, filter and paginate the victim timeline for Yanluowang. Showing 1–6 of 6.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Hot news straight from Cisco id3942 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Shorr.com leakage id3713 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Greetings to havi.com and tmsw.com id3712 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Big data dump from various organizations id3711 View details | NGOs / Associations | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Walmart was encrypted id3710 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cincinnati bell didn’t pay the ransom id3709 View details | Services | — | ||
|
No additional victim description available. |
|||||