A new and still-developing strain of ransomware is being used in highly targeted attacks against business entities, Symantec Threat Hunter Team has discovered. The malware is called Yanluowang ransomware because of the extension it adds to encrypted files on compromised systems.
See also: New Python ransomware: Encrypts system within three hours

It was recently discovered during the investigation of an incident involving a high-profile organization after suspicious activity was detected involving the legitimate AdFind command-line Active Directory tool.
AdFind is commonly used by ransomware operators for reconnaissance tasks, including accessing information needed for lateral movement through their victims' networks.
See also: Global ransomware meetings: Russia and China left out
The victims were warned not to seek help
In the days that researchers detected the suspicious use of AdFind, the attackers attempted to deploy the Yanluowang ransomware payloads to the compromised organization's systems.
Before deployment to compromised devices, ransomware operators launch a malicious tool designed to perform the following actions:
- Creates a .txt file with the number of remote machines to check on the command line
- Uses Windows Management Instrumentation (WMI) to obtain a list of processes running on the remote machines referenced in the .txt file
- Records all processes and remote machine names in processes.txt
Once deployed, Yanluowang will stop hypervisor virtual machines, terminate all processes collected by the precursor tool (including SQL and Veeam), encrypt files, and append the .yanluowang extension.
On encrypted systems, Yanluowang drops a ransom note named README.txt that warns its victims not to contact law enforcement or seek help from ransomware negotiation firms.
Threats of DDoS attacks
"If the attackers' rules are violated, ransomware operators say they will launch denial of service (DDoS) against the victim," Broadcom researchers added.
"The criminals also threaten to repeat the attack" in a few weeks "and delete the victim's data," a common tactic used by most ransomware gangs to pressure their victims into paying the ransom.
See also: Pacific City Bank attacked by AvosLocker ransomware
Although it is under development, Yanluowang is still dangerous malware given that ransomware is one of the biggest threats facing organizations worldwide.
The White House National Security Council is this week holding a series of meetings between senior officials from more than 30 countries in a virtual global event to combat ransomware attacks.
Information source: bleepingcomputer.com
