Kaspersky disclosed today that it found a vulnerability in the encryption algorithm of the Yanluowang ransomware, which makes it possible to recover files it encrypts.

Yanluowang is a type of targeted ransomware that was discovered by the Symantec Threat Hunter team while they were investigating an incident in a large corporate network.
See also: Fake Windows 11 upgrade installs malware
The Russian cybersecurity company added support to the RannohDecryptor utility for decrypting files that are locked by the Yanluowang ransomware core.
"Kaspersky experts analyzed the ransomware and found a vulnerability that allows decryption of affected users via a known-plaintext attack," the company said today.
This ransomware stem encrypts files larger than 3 GB and smaller than 3 GB using different methods: the larger ones are partially encrypted in 5MB stripes after each 200 MB, while the smaller ones are fully encrypted from start to finish.
Because of this, “if the original file is larger than 3 GB, it is possible to decrypt all files on the infected system, both large and small. But if there is an original file smaller than 3 GB, then only small files can be decrypted.”
See also: iPhone: Zero-click exploit used in NSO spyware attacks
To decrypt your files, you need at least one of the original files:
- To decrypt small files (less than or equal to 3 GB), you need a pair of files sized 1024 bytes or more. This is sufficient to decrypt all other small files.
- To decrypt large files (more than 3 GB), you need a pair of files (encrypted and original) sized at least 3 GB each. This will be sufficient to decrypt both large and small files.
To decrypt files encrypted by Yanluowang ransomware, you need to use the Rannoh decryption tool available for download from Kaspersky servers.

Yanluowang attacks high-profile corporate targets
Yanluowang ransomware, which was first detected in October 2021, has been used in human-based, highly targeted attacks against business entities.
A month later, one of their affiliates was observed attacking American organizations in the financial sector since at least August, using the BazarLoader malware for identification.
Based on the tactics, techniques, and procedures (TTPs) used in these attacks, this Yanluowang affiliate was linked to the Thieflock ransomware operation developed by the Fivehands team (which is tracked by Mandiant as UNC2447).
Once deployed on compromised networks, Yanluowang stops hypervisor virtual machines, terminates all processes, and encrypts files by attaching the .yanluowang extension.
It also displays ransom notes named README.txt that warn victims not to contact law enforcement or seek help from ransom-trading companies.
See also: Pixel 6 bug: Some calls are automatically rejected without your knowledge
If the attackers' demands are not met, ransomware operators threaten to launch distributed denial of service (DDoS) attacks against victims' networks and inform their employees and business partners that they have been breached.
They also say they will breach the victims' networks again “in a few weeks” and will delete their data, a common tactic used by ransomware gangs to pressure their victims to pay the ransom.
Information source: bleepingcomputer.com
