Description Summary
According to PCrisk, Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the README.txt file containing a ransom note. It appends the .yanluowang extension to filenames. Cybercriminals behind Yanluowang are targeting enterprise entities and organizations in the financial sector. Files encrypted by Yanluowang can be decrypted with this tool (it is possible to decrypt all files if the original file is larger than 3GB. If the original file is smaller than 3GB, then only smaller files can be decrypted).
Threat Actor
Targeted enterprises and the financial sector; linked to the 2022 Cisco breach. A flaw enabled free decryption of older files.
Technical Indicators
Encryption Extension
.yanluowang
Encryption Algorithm
Sosemanuk (stream cipher) + RSA-2048
Ransom Note Name
README.txt
Targeted Industries
Financial, Manufacturing, Enterprise
First Seen
August 2021
Last Seen
2022 (builder/chat logs leaked; Kaspersky released a decryptor for a crypto flaw)
Geographical Location
United States
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |