CSIDB logo
Threat actor

Yanluowang

Attribution profile

Type
Crime Syndicate
Location
Russia
Known incidents
1 incident
First seen
2022-10-31
Last seen
2022-10-31
Updated
2026-07-30 21:33
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as Yanluowang, also tracked under the alias @yanluowangleaks, is identified as a ransomware group associated with Russian language communications. Public reporting indicates the group maintained an extortion site used to publish victim data and negotiate payments. The group’s location is noted as Russia, based on available open‑source information.

On October 31, 2022, a message appeared on the group’s extortion site announcing that its internal Matrix chat channel had been compromised. Approximately 2,700 messages exchanged between January and September 2022 were exfiltrated and posted to a leak site. The leaked correspondence was conducted primarily in Russian, allowing analysts to read the discussions directly. Researchers who examined the logs reported that the chats revealed the group’s tactics, techniques, and procedures, including details about how they conducted operations. The material also showed possible interactions with other ransomware families and offered insight into the gang’s internal hierarchy and role assignments.

The exposure of these internal communications provided law enforcement, rival threat actors, and cybersecurity investigators with a rare view into the group’s operational security shortcomings. Analysis of the logs helped clarify how Yanluowang organized its affiliate network and managed extortion negotiations. While the breach did not disclose any specific victim sectors or geographic focus, it underscored the importance of secure communications for ransomware enterprises. No further public campaigns attributed to Yanluowang have been detailed in the sources examined.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB