Skip to content

Malware

Yanluowang

aka Dryxiphia

According to PCrisk, Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the "README.txt" file containing a ransom note.

Yanluowang, also known as Dryxiphia, is a Windows malware family.

Background

PCrisk describes Yanluowang as ransomware that locks and renames files, terminates active processes, halts services, and drops a "README.txt" ransom note. Affected files receive the ".yanluowang" extension. The operators behind it focus their attacks on enterprises and organizations within the financial industry.

A decryption tool exists for files locked by Yanluowang: when the original file exceeds 3GB, every file can be recovered, but if it is under 3GB, recovery is limited to the smaller files.


Source: Malpedia (Fraunhofer FKIE).