Yanluowang Ransomware

Description Summary

According to PCrisk, Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the README.txt file containing a ransom note. It appends the .yanluowang extension to filenames. Cybercriminals behind Yanluowang are targeting enterprise entities and organizations in the financial sector. Files encrypted by Yanluowang can be decrypted with this tool (it is possible to decrypt all files if the original file is larger than 3GB. If the original file is smaller than 3GB, then only smaller files can be decrypted).

Threat Actor

Targeted enterprises and the financial sector; linked to the 2022 Cisco breach. A flaw enabled free decryption of older files.

Technical Indicators

Encryption Extension
.yanluowang
Encryption Algorithm
Sosemanuk (stream cipher) + RSA-2048
Ransom Note Name
README.txt
Targeted Industries
Financial, Manufacturing, Enterprise
First Seen
August 2021
Last Seen
2022 (builder/chat logs leaked; Kaspersky released a decryptor for a crypto flaw)
Geographical Location
United States

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts