Well-known American retailer Walmart has denied being attacked by ransomware from the Yanluowang gang , following the hackers ' claims of encrypting thousands of computers .

According to BleepingComputer, Walmart said its Information Security team monitors the company's systems every day, 24 hours a day, and believes the claims are inaccurate.
See also: YTStealer malware steals accounts from YouTube creators
"We believe this claim is inaccurate, we are not aware of any successful attack on devices our," a Walmart spokesperson told BleepingComputer.
Is that exactly what happened?
On Monday, the hackers behind the relatively new ransomware operation, Yanluowang, posted an leak site data their and reported that they had breached Walmart, encrypting an estimated 40,000 to 50,000 devices.
“We encrypted about 40-50,000 Walmart computers and offered our help, but they decided to go the other way and so we are publishing,” the hackers report on the data leak site.
Also, according to BleepingComputer, the ransomware gang said they carried out the attack more than a month ago and were able to encrypt devices, but did not steal any data. As part of this attack, they say they demanded a ransom of $55 million, but never received a response from Walmart.
See also: Evilnum returns targeting immigration organizations

So the hackers decided to publicize the attack, making this post on the data leak site, where they have also included various files that claim to contain information extracted during the attack from Walmart's Windows domain.
As we said above, Walmart denies that the attack was successful, but these files contain information that claims to come from Walmart's internal network, including a security, a list of domain users, and other elements linked to a kerberosting attack.
Kerberosting is used by threat actors, after gaining access to a network, to extract Windows service accounts and hashed NTLM passwords. Attackers then brute-force to extract plain-text passwords, which are used to escalate privileges in the Windows domain.
See also: Messenger: Malicious chatbots steal credentials for Facebook pages
At present, it has not been confirmed whether the data leaked by the Yanluowang ransomware gang is authentic and belongs to Walmart.
Source: www.bleepingcomputer.com
