Threats Tagged 'yurei'
View all threats tagged with 'yurei'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'yurei'
Click on any threat for detailed analysis and mitigation recommendations
Yurei ransomware, identified in September 2025, targets corporate networks primarily in transportation, IT, marketing, and food sectors. Developed in Go, it uses strong encryption algorithms ChaCha20-Poly1305 for file encryption and secp256k1-ECIES for key protection. The ransomware excludes certain files and directories to maintain system operability. Each file is encrypted with a unique key and nonce, ensuring only the attacker can decrypt the data. The ransom note threatens data leaks and regulatory notifications if demands are unmet within five days. While currently observed in Sri Lanka and Nigeria, the ransomware’s sophisticated encryption and typical corporate targeting pose a medium-level threat globally. No known exploits in the wild or CVEs exist yet. European organizations should be vigilant due to potential expansion and regulatory impact. Mitigation requires proactive network segmentation, strict access controls, and advanced detection of lateral movement and privilege escalation. Join the discussion | AlienVault OTX General | 11/14/2025, 12:16:01 UTC Added: 11/14/2025, 12:31:21 UTC |
A sophisticated ransomware family called Yurei has emerged, targeting Windows systems with advanced encryption methods. It rapidly encrypts data using ChaCha20 and ECIES, appends .Yurei to files, and disables recovery options. The malware spreads via SMB shares, removable drives, and credential-based remote execution. It employs anti-forensics techniques, including log wiping and secure deletion. Yurei features double-extortion capabilities, threatening data leaks alongside ransom demands. Analysis suggests possible code reuse from the Prince ransomware. The ransomware's professional build, stealthy propagation, and high operational speed make it a significant threat designed for irreversible data compromise. Join the discussion | AlienVault OTX General | 10/04/2025, 09:22:35 UTC Added: 10/06/2025, 08:00:43 UTC |
Yurei, a newly emerged ransomware group, targeted a Sri Lankan food manufacturing company on September 5, 2025. The group employs a double-extortion model, encrypting files and exfiltrating sensitive data. Check Point Research discovered that Yurei's ransomware is based on the open-source Prince-Ransomware, with minor modifications. The ransomware, written in Go, contains a flaw allowing partial recovery through Shadow Copies. Since its first victim, Yurei has quickly expanded to three victims across Sri Lanka, India, and Nigeria. The investigation suggests the threat actor may originate from Morocco. Yurei's operation demonstrates how open-source malware lowers the entry barrier for cybercriminals, enabling less-skilled actors to launch ransomware attacks. Join the discussion | AlienVault OTX General | 09/12/2025, 15:33:53 UTC Added: 09/12/2025, 19:32:15 UTC |
Showing 1 to 3 of 3 results