Uptime Hamster: 10d 11h 38mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza yanluowang

yanluowang

2 incidentes 2 paises 0 sectores ransomware RU Ultimo: 2026-07-09
Aliases: Dryxiphia
Ver en IntelTracker → APTTrail →
Yanluowang is a human-operated ransomware group that emerged in July 2021, though it was first publicly identified in October 2021 by Symantec's Threat Hunter Team. The group ceased operations in late 2022 following a significant leak of its internal chat logs and source code. Despite its name, which derives from Chinese mythology, the group is assessed with high confidence to be of Russian origin, with operators intentionally feigning a Chinese identity to mislead analysts. Yanluowang's primary motivation is financial gain, achieved through targeted ransomware attacks and a double extortion model. The group distinguished itself through its specific operational pattern, which included halting hypervisor virtual machines and terminating processes such as SQL and Veeam before encrypting files. Additionally, Yanluowang threatened victims with Distributed Denial of Service (DDoS) attacks and outreach to employees and business partners if ransom demands were not met. The group is also known

Aliases del actor

Dryxiphia
Tecnicas MITRE
T1566.001, T1078, T1059, T1486, T1021.001
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1) China (1)

Paises objetivo (SOCRadar)

United Arab EmiratesBrazilCanadaChinaGermanyFinlandTurkeyUnited States

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesRail TransportationSoftware PublishersReal EstateEnterprises & HoldingManufacturingPublic AdministrationEducational ServicesWholesale Trade

Victimas (1)

Yanluowang (China)9 Jul 2026
Reference China
Que es Yanluowang es un actor APT (Advanced Persistent Threat) asociado a China, identificado como una organización de ciberataques con actividades pe…