Yurei the New Ransomware Group on the Scene
Sept. 15, 2025, 7:04 p.m.
Description
Yurei, a newly emerged ransomware group, targeted a Sri Lankan food manufacturing company on September 5, 2025. The group employs a double-extortion model, encrypting files and exfiltrating sensitive data. Check Point Research discovered that Yurei's ransomware is based on the open-source Prince-Ransomware, with minor modifications. The ransomware, written in Go, contains a flaw allowing partial recovery through Shadow Copies. Since its first victim, Yurei has quickly expanded to three victims across Sri Lanka, India, and Nigeria. The investigation suggests the threat actor may originate from Morocco. Yurei's operation demonstrates how open-source malware lowers the entry barrier for cybercriminals, enabling less-skilled actors to launch ransomware attacks.
Tags
Date
- Created: Sept. 12, 2025, 3:33 p.m.
- Published: Sept. 12, 2025, 3:33 p.m.
- Modified: Sept. 15, 2025, 7:04 p.m.
Indicators
- d2539173bdc81503bf1b842a21d9599948e957cadc76a283a52f5849323d8e04
- 89a54d3a38d2364784368a40ab228403f1f1c1926892fe8355aa29d00eb36819
- 1ea37e077e6b2463b8440065d5110377e2b4b4283ce9849ac5efad6d664a8e9e
- 0303f89829763e734b1f9d4f46671e59bfaa1be5d8ec84d35a203efbfcb9bb15
- fewcriet5rhoy66k6c4cyvb2pqrblxtx4mekj3s5l4jjt4t4kn4vheyd.onion
Additional Informations
- Manufacturing
- British Indian Ocean Territory
- Nigeria
- Sri Lanka
- India