Ransomware-as-a-service (RaaS) group Yanluowang’s leaked Matrix chat messages offered valuable intel on its inner workings, possible affiliations with other Russian ransomware families, and the sophisticated ecosystem, Trellix found.
The gang’s TOR site was hacked on October 31, and some of its Matrix chat messages were shared by a Twitter handle @yanluowangleaks on the same day. This included around 2,700 messages from mid-January to September 2022, according to the security vendor.
Yanluo Wang is a Chinese deity and the name seems to suggest the RaaS group is potentially of Chinese origin, but all the leaked chats were in Russian.
“Yanluowang is a Russian ransomware group and it appears that they were masquerading at the beginning as Chinese using the Yanluo Wang logo on their lead page. But it turned out to be that all the messages were in Russian. There were no Chinese at all,” Trellix Security Researcher Jambul Tologonov told SDxCentral.
The leaked chats didn’t mention why the group chose that name, but Tologonov reckons they might want to avoid negativity around Russian-based ransomware groups. And in one of the discussions the gang explored positioning themselves as Ukrainian to increase their chances of ransom being paid, but later dropped the idea concerned it would blow up its Chinese threat actor cover story, he added.
Potential Collaboration With Other Russian Ransomware GroupsThe leaked messages showed hints of Yangluowang’s collaboration with other ransomware groups, possibly HelloKitty, Babuk, Conti, and LockBit.
“The most interesting thing for me was to find links to other Russian ransomware families, like the Babuk, HelloKitty, and Conti,” Tologonov said, referring to his analysis of the leaked messages.
One person possibly behind the HelloKitty gang joined Yanluowang’s Matrix room chat in mid-May, and mentioned they had working credentials for dozens of companies. However, that person was concerned their two-man team could not follow up on those by themselves and looked for some kind of collaboration with Yangluowang on those attacks, according to Tologonov.
The same person was potentially also involved in the hack targeting Cisco in May. Yanluowang published a list of files it claimed were stolen from Cisco to the dark web in August.
“Later in September, they were discussing that the attack wasn't that successful, and Cisco really didn't want to cooperate,” Tologonov said.
He also found Yanluowang used a Linux locker from the Babuk group before it developed its own Linux/Unix ransomware locker.
Additionally, the Trellix research team investigated a bitcoin address mentioned in one of the leaked messages and found a possible link to Conti ransomware bitcoin wallets. The two groups had similar schemes for cashing out bitcoin, exchanging bitcoin to Monero and then to cash via local exchange offices in large cities.
Another message also showed a Yanluowang member exchanging bitcoin to QR codes via LockBit.
“He was saying that he cashes out money via QR services provided by LockBit. And it wasn't clear to us what is the connection between Yanluowang and LockBit, but seems like LockBit has some sort of cash-out services [that] they provide to certain cybercriminals where you just transfer money from bitcoin directly to their accounts and get the cash,” Tologonov explained.
Yanluowang Shuts Down Operations After the LeakYanluowang shut down its operations after its lead page was compromised, though Tologonov said it could regroup.
“Since then, we haven't observed any activity specifically from Yanluowang," he said. "Even the Twitter account, last time I checked, [who] was leaking the Matrix chat of Yanluowang, is now suspended as well."
However, “it doesn't mean that they will disappear … since the ecosystem is so agile and adaptable, they always cooperate with each other. It could be that they either come up with a new ransomware group or they'll just disperse into the existing initiatives.”
The Conti ransomware group dropped the brand after a series of data leaks earlier this year and potentially split into smaller groups.
“Conti and Yanluowang leaks, which happened in 2022, are unprecedented. It's the first time we're able to see the inner workings and how organized they are. They're not just a group of unskilled specialists. They are complicated, government-backed, and they are so sophisticated they have their developers department, coders department, testers department, HR, payroll,” Tologonov said.
“And for me it was very interesting most of the time, like eye-opening to realize how much they resembled just ordinary firms and how easy for them to reach out to other ransomware gangs and suggest new initiatives, or if for instance, they have a possible way to compromise a network but they're too busy with something they just might hand it over to other affiliates,” he added.
Comments