← All ransomware groups

Ransomware group profile · #240 by claimed victims

Yanluowang ransomwarealso Storm-0866

A small crew that targeted a narrow set of large organisations rather than operating at volume. Its internal coordination is documented in unusual detail for an operation of its size: six rooms, a handful of operators, and the whole of their day-to-day traffic.

Defunct Russia First seen Aug 2021 Sosemanuk stream cipher with an RSA wrapped key Russian
6Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
0Countries hit
1Leak-site URLs tracked, 0 online
10 Aug 2022Latest claim recorded

Victimology

Who Yanluowang claims to have breached, from 6 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Technology2
Retail & E-Commerce2

Top countries

No country data yet.

Latest claimed victims 6 most recent

VictimSectorCountryClaimed
Hot news straight from Cisco Technology 10 Aug 2022
Shorr.com leakage shorr.com leakage Retail & E-Commerce 2 Jul 2022
Greetings to havi.com and tmsw.com greetings to havi.com and tmsw.com Not Found 2 Jul 2022
Big data dump from various organizations Not Found 2 Jul 2022
Walmart was encrypted Retail & E-Commerce 2 Jul 2022
Cincinnati bell didn’t pay the ransom Technology 2 Jul 2022

All 6 Yanluowang victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Yanluowang is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Yanluowang ransomware still active?
Yanluowang is tracked as defunct. The most recent leak-site claim VULONE recorded is dated 10 August 2022.
How many victims has Yanluowang claimed?
VULONE has recorded 6 leak-site victim claims attributed to Yanluowang since July 2022, across 0 countries and 3 sectors.
Which industries does Yanluowang target?
The sectors most often named on the Yanluowang leak site are Technology, Retail & E-Commerce.
Which countries are most affected by Yanluowang?
Country data for Yanluowang victims is not yet available.
Where does VULONE get Yanluowang victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Public sources

TitlePublisherDate
VULONE primary-source researchVULONE

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].