Skip to main content

Threats Tagged 'yurei'

View all threats tagged with 'yurei'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: yurei

Threats Tagged 'yurei'

Click on any threat for detailed analysis and mitigation recommendations

Yurei ransomware, identified in September 2025, targets corporate networks primarily in transportation, IT, marketing, and food sectors. Developed in Go, it uses strong encryption algorithms ChaCha20-Poly1305 for file encryption and secp256k1-ECIES for key protection. The ransomware excludes certain files and directories to maintain system operability. Each file is encrypted with a unique key and nonce, ensuring only the attacker can decrypt the data. The ransom note threatens data leaks and regulatory notifications if demands are unmet within five days. While currently observed in Sri Lanka and Nigeria, the ransomware’s sophisticated encryption and typical corporate targeting pose a medium-level threat globally. No known exploits in the wild or CVEs exist yet. European organizations should be vigilant due to potential expansion and regulatory impact. Mitigation requires proactive network segmentation, strict access controls, and advanced detection of lateral movement and privilege escalation.

Join the discussion

A sophisticated ransomware family called Yurei has emerged, targeting Windows systems with advanced encryption methods. It rapidly encrypts data using ChaCha20 and ECIES, appends .Yurei to files, and disables recovery options. The malware spreads via SMB shares, removable drives, and credential-based remote execution. It employs anti-forensics techniques, including log wiping and secure deletion. Yurei features double-extortion capabilities, threatening data leaks alongside ransom demands. Analysis suggests possible code reuse from the Prince ransomware. The ransomware's professional build, stealthy propagation, and high operational speed make it a significant threat designed for irreversible data compromise.

Join the discussion

Yurei, a newly emerged ransomware group, targeted a Sri Lankan food manufacturing company on September 5, 2025. The group employs a double-extortion model, encrypting files and exfiltrating sensitive data. Check Point Research discovered that Yurei's ransomware is based on the open-source Prince-Ransomware, with minor modifications. The ransomware, written in Go, contains a flaw allowing partial recovery through Shadow Copies. Since its first victim, Yurei has quickly expanded to three victims across Sri Lanka, India, and Nigeria. The investigation suggests the threat actor may originate from Morocco. Yurei's operation demonstrates how open-source malware lowers the entry barrier for cybercriminals, enabling less-skilled actors to launch ransomware attacks.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: yurei
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses