Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria. Known victims: 3

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

The Yurei threat actor emerged in September 2025 as a ransomware group targeting critical sectors such as food manufacturing, transportation, and IT in Sri Lanka and Nigeria. Utilizing a modified Prince-Ransomware variant with ChaCha20 encryption, Yurei propagates via SMB shares to maximize impact. Their primary goal is financial gain through ransom payments.

Goals & Targeting

Yurei targets sectors critical to daily operations—food manufacturing and transportation—to ensure high impact and willingness to pay ransoms. The group's focus on Sri Lanka and Nigeria may indicate an initial strategic choice to exploit regions with less mature cybersecurity defenses, yet significant economic stakes in maintaining essential services. Their modus operandi suggests a goal of achieving organizational gain through financial extraction.

Enhanced Description

Yurei is a newly emerged ransomware group first identified in September 2025. The group operates with a modified Prince-Ransomware variant, leveraging ChaCha20 encryption for data protection and spreading via SMB shares to compromise internal networks. Targeting sectors like food manufacturing, transportation, and IT, Yurei focuses on regions where such disruptions can lead to significant economic impact. Their criminal motivation, coupled with the use of readily available ransomware frameworks, suggests a mid-tier operational sophistication. While their activities are still emerging, Yurei demonstrates a clear intent to maximize profit through disruption.

Key Capabilities

  • Ransomware deployment
  • SMB propagation
  • ChaCha20 encryption implementation
  • Network scanning and lateral movement

MITRE ATT&CK Tactics

Lateral Movement
Exfiltration
Credential Access
Encryption
Defense Evasion

ATT&CK Techniques

T1566.001
T1040
T1569.001
T1055
T1583.001

Software / Tooling

Prince-Ransomware (modified)
SMB protocol exploit tools

Campaigns & Victims

Yurei's initial operations indicate a focus on rapid deployment and limited scope, targeting three known victims across the specified sectors. Their operational tempo suggests cautious expansion, possibly to assess victim response before scaling activities. Notable for their use of open-source frameworks and minimal modification, Yurei may aim to refine their tactics based on early successes.

IOC Patterns

  • Propagation via SMB shares
  • ChaCha20 encryption in ransomware payloads
  • Use of modified Prince-Ransomware framework

Recommended Actions

  • Implement strong SMB share permissions and disable unnecessary SMB services.
  • Monitor for signs of lateral movement within networks using network segmentation.
  • Educate employees on phishing and suspicious emails to mitigate potential initial access vectors.
  • Encrypt sensitive data at rest and in transit with robust cryptographic measures.

Suggested Tags

Ransomware
Criminal
Organized Crime
Food Manufacturing
Transportation

Confidence Assessment

Moderate confidence in threat actor details, based on limited observed activity. Additional analysis is recommended to identify further IOCs and understand long-term strategic goals.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Criminal
Organized Crime
Food Manufacturing
Transportation

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Sep 5, 2025
Last Seen
Sep 9, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.