Yurei

Inactive
Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.
3 Victims
Sep 5, 2025 First Discovered
Sep 9, 2025 Last Discovered
282 Days Inactive
0% Infostealer
0/1 Sites Online
Top Countries
CH 1
NG 1
LK 1
Top Sectors
Energy 1
Consumer Services 1
Agriculture and Food Production 1
Known Locations (1)
Yurei Blog
fewcriet5rhoy66k6c4cyvb2pqrblxtx4mekj3s5l4jjt4t4kn4vheyd.onion
Tools Used
DiscoveryEnum
Everything.exe, SoftPerfect NetScan
LOLBAS
PsExec, SDelete
Offsec
Invoke-TheHash, NetExec, Rubeus, WinPEAS
RMM-Tools
AnyDesk
Victims (3)
noblecorp.net
CH Energy Discovered: Sep 9, 2025 · Attack est.: Sep 9, 2025
Noble Corporation is a leading industrial insulation and materials supply company based in India, renowned for its expertise, innovation, and dedication to quality. Established in 1935, the company has steadily...
www.thepromisenig.com
NG Consumer Services Discovered: Sep 8, 2025 · Attack est.: Sep 8, 2025
The Promise Nigeria Ltd is a leading brand in Nigeria’s fast-food and catering industry, renowned for its dedication to quality, freshness, and customer satisfaction. Established in 2000 and incorporated in...
www.midcity.lk
LK Agriculture and Food Production Discovered: Sep 5, 2025 · Attack est.: Sep 5, 2025
Midcity Marketing (Pvt) Ltd, Sri Lanka is a dominant force in the import, distribution, and marketing of essential dry food commodities. Since its establishment in 1995, the company has built...