CSIDB logo
Organisation

Yanluowang

Profile

Primary URL
Undetermined
Location
Russia
Sector
Technology
Known incidents
1 incident
Updated
2026-08-11 03:34
Aliases
2 aliases

Organisation tracking is available to eligible accounts.

Profile narrative

Yanluowang, also known as the Yanluowang ransomware gang, is a cybercriminal organization that specializes in ransomware attacks. The group gains unauthorized access to victim networks, deploys ransomware to encrypt files, and then demands payment for decryption keys. In addition to encryption, Yanluowang typically threatens to publish stolen data unless the ransom is paid, a tactic known as double extortion. The gang operates an extortion site where it posts victim data to increase pressure on targets. Based on available information, the group’s primary language of operation is Russian and its headquarters are located in Russia.

On October 31, 2022, Yanluowang suffered a significant security breach when its extortion site was compromised by an unknown actor. The breach resulted in the exposure of approximately 2,700 internal chat messages that had been exchanged over several months. These communications were conducted primarily in Russian and covered a range of topics related to the group’s activities. Analysis of the leaked chats revealed details about the gang’s tactics, techniques, and procedures, as well as possible collaborations with other ransomware actors. The leak also provided insights into Yanluowang’s internal organizational structure and undermined its operational security.

The incident highlighted Yanluowang’s reliance on chat platforms for coordination and the sensitivity of such communications to operational security. The disclosed TTPs included methods for initial access, lateral movement, and data exfiltration that are characteristic of modern ransomware operations. The possibility of collaborations mentioned in the chats suggests the group may engage in information sharing or joint ventures with other criminal entities. These distinguishing attributes—Russian‑language focus, double‑extortion model, and use of internal chat for planning—set Yanluowang apart from less sophisticated ransomware groups.

The only explicit structural detail available about Yanluowang is that its headquarters are situated in Russia. No public sources disclose the group’s ownership, parent‑company relationships, or subsidiary structure. Consequently, any description of Yanluowang’s corporate hierarchy remains unspecified in the current record.

Incidents

1 incident linked to this organisation.

CSIDB