Yanluowang
Aliases: Dryxiphia
- First seen
- 2021-11-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:10:39
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications manufacturing
Targeted regions: country_code:us country_code:ca country_code:gb country_code:fr
Context
Yanluowang is a ransomware strain known for encrypting files and demanding cryptocurrency payment. It has been associated with double extortion tactics, where sensitive data is also stolen and threatened to be released.
Detection coverage
- 2 YARA rules
Detection rules
- ARKBIRD_SOLG_RAN_Yanluowang_Dec_2021_1 (yara-rule)
- MALPEDIA_Win_Yanluowang_Auto (yara-rule)
Reports & references
- Cisco Talos — Recent Cyber Attack (report)
- Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
- github.com — Ransomware Windows Yanluowang (report)
- Kaspersky — 106332 (report)
- Broadcom/Symantec — Yanluowang Targeted Ransomware (report)
- bleepingcomputer.com — Free Decryptor Released For Yanluowang Ransomware Victims (report)
- ransomlook.io — Yanluowang (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Yanluowang (report)
- twitter.com — 1586967110504398853 (report)
- therecord.media — The Yanluowang Ransomware Group In Their Own Words (report)
- de.darktrace.com — Inside The Yanluowang Leak Organization Members And Tactics (report)