Yurei

Inactive
Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.
3 Victims
Sep 5, 2025 First Discovered
Sep 9, 2025 Last Discovered
372 Days Inactive
0% Infostealer
0/1 Sites Online
Top Countries
CH 1
NG 1
LK 1
Top Sectors
Energy & Utilities 1
Retail & E-Commerce 1
Agriculture and Food Production 1
Known Locations (1)
Yurei Blog
fewcriet5rhoy66k6c4cyvb2pqrblxtx4mekj3s5l4jjt4t4kn4vheyd.onion
Tools Used
DiscoveryEnum
Everything.exe, SoftPerfect NetScan
LOLBAS
PsExec, SDelete
Offsec
Invoke-TheHash, NetExec, Rubeus, WinPEAS
RMM-Tools
AnyDesk
Victims (3)
noblecorp.net
CH Energy & Utilities Discovered: Sep 9, 2025 · Attack est.: Sep 9, 2025
Noble Corporation is a leading industrial insulation and materials supply company based in India, renowned for its expertise, innovation, and dedication to quality. Established in 1935, the company has steadily...
www.thepromisenig.com
NG Retail & E-Commerce Discovered: Sep 8, 2025 · Attack est.: Sep 8, 2025
The Promise Nigeria Ltd is a leading brand in Nigeria’s fast-food and catering industry, renowned for its dedication to quality, freshness, and customer satisfaction. Established in 2000 and incorporated in...
www.midcity.lk
LK Agriculture and Food Production Discovered: Sep 5, 2025 · Attack est.: Sep 5, 2025
Midcity Marketing (Pvt) Ltd, Sri Lanka is a dominant force in the import, distribution, and marketing of essential dry food commodities. Since its establishment in 1995, the company has built...