Yanluowang is a ransomware group that emerged in mid-2022, operating with primarily financial motivations through targeted attacks against organizations. The group's origin and potential state affiliations remain largely undocumented by major security firms, though they appear to operate independently rather than as a ransomware-as-a-service model. Limited public reporting from established threat intelligence sources provides few details about their specific attack methodologies, initial access vectors, or whether they employ double extortion tactics involving data theft prior to encryption. The group has maintained a relatively low profile with approximately six documented victims, showing a particular focus on targeting media sector organizations. Despite the limited scope of their publicly known operations, Yanluowang appears to remain active as of current reporting, though their small victim count and sector-specific targeting suggest they may be a smaller-scale operation compared to more prominent ransomware families. The group has been linked to 6 public disclosures across our corpus. First observed on a leak site on July 2, 2022; most recent post August 10, 2022. The operation is currently inactive.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.