Skip to content

yurei

Inactive

3 tracked victims · First seen Sep 5, 2025 · Last seen Sep 9, 2025

About

Aggregated threat-intel description

Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.

Sectors: Energy · Countries: CH, LK, NG

Recent victims

View all →
VictimSectorCountryPostedStatus
noblecorp.netEnergyCHSep 9, 2025
www.thepromisenig.comNot FoundNGSep 8, 2025
www.midcity.lkNot FoundLKSep 5, 2025

All ransomware groups · Dark web intelligence