HomeSecurityYanluowang Ransomware: Used in attacks against businesses

Yanluowang Ransomware: Used in attacks against businesses

A new and still-developing strain of ransomware is being used in highly targeted attacks against business entities, Symantec Threat Hunter Team has discovered. The malware is called Yanluowang ransomware because of the extension it adds to encrypted files on compromised systems.

See also: New Python ransomware: Encrypts system within three hours

Yanluowang

It was recently discovered during the investigation of an incident involving a high-profile organization after suspicious activity was detected involving the legitimate AdFind command-line Active Directory tool.

AdFind is commonly used by ransomware operators for reconnaissance tasks, including accessing information needed for lateral movement through their victims' networks.

See also: Global ransomware meetings: Russia and China left out

The victims were warned not to seek help

In the days that researchers detected the suspicious use of AdFind, the attackers attempted to deploy the Yanluowang ransomware payloads to the compromised organization's systems.

Before deployment to compromised devices, ransomware operators launch a malicious tool designed to perform the following actions:

  • Creates a .txt file with the number of remote machines to check on the command line
  • Uses Windows Management Instrumentation (WMI) to obtain a list of processes running on the remote machines referenced in the .txt file
  • Records all processes and remote machine names in processes.txt

Once deployed, Yanluowang will stop hypervisor virtual machines, terminate all processes collected by the precursor tool (including SQL and Veeam), encrypt files, and append the .yanluowang extension.

On encrypted systems, Yanluowang drops a ransom note named README.txt that warns its victims not to contact law enforcement or seek help from ransomware negotiation firms.

Threats of DDoS attacks

"If the attackers' rules are violated, ransomware operators say they will launch denial of service (DDoS) against the victim," Broadcom researchers added.

"The criminals also threaten to repeat the attack" in a few weeks "and delete the victim's data," a common tactic used by most ransomware gangs to pressure their victims into paying the ransom.

See also: Pacific City Bank attacked by AvosLocker ransomware

Although it is under development, Yanluowang is still dangerous malware given that ransomware is one of the biggest threats facing organizations worldwide.

The White House National Security Council is this week holding a series of meetings between senior officials from more than 30 countries in a virtual global event to combat ransomware attacks.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS