New "Yanluowang" Ransomware Variant Discovered
Security researchers are warning of a newly discovered ransomware variant currently being used in targeted attacks.
Dubbed “Yanluowang” after the .yanluowang extension it adds to encrypted files, the new ransomware was discovered by Symantec during its investigation into an attack against an unnamed “large organization.”
It appears that the group using the variant first deployed legitimate command-line Active Directory query tool AdFind for reconnaissance and to help with lateral movement.
Before Yanluowang is downloaded, an additional tool creates a .txt file with the number of remote machines to check in the command line and uses WMI to get a list of processes running on these machines.
It also logs all the processes and remote machine names, Symantec said.
Then, following deployment, the malware stops all hypervisor machines running on the targeted machine, ends the processes listed in the .txt file, encrypts the files and drops a ransom note named README.txt.
The note purpotedly warns victims not to contact the police or any specialized ransomware negotiation firms.
“If the attackers’ rules are broken the ransomware operators say they will conduct distributed denial of service (DDoS) attacks against the victim, as well as make