Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria. Known victims: 3
Objectives
Executive Summary
The Yurei threat actor emerged in September 2025 as a ransomware group targeting critical sectors such as food manufacturing, transportation, and IT in Sri Lanka and Nigeria. Utilizing a modified Prince-Ransomware variant with ChaCha20 encryption, Yurei propagates via SMB shares to maximize impact. Their primary goal is financial gain through ransom payments.
Goals & Targeting
Yurei targets sectors critical to daily operations—food manufacturing and transportation—to ensure high impact and willingness to pay ransoms. The group's focus on Sri Lanka and Nigeria may indicate an initial strategic choice to exploit regions with less mature cybersecurity defenses, yet significant economic stakes in maintaining essential services. Their modus operandi suggests a goal of achieving organizational gain through financial extraction.
Enhanced Description
Yurei is a newly emerged ransomware group first identified in September 2025. The group operates with a modified Prince-Ransomware variant, leveraging ChaCha20 encryption for data protection and spreading via SMB shares to compromise internal networks. Targeting sectors like food manufacturing, transportation, and IT, Yurei focuses on regions where such disruptions can lead to significant economic impact. Their criminal motivation, coupled with the use of readily available ransomware frameworks, suggests a mid-tier operational sophistication. While their activities are still emerging, Yurei demonstrates a clear intent to maximize profit through disruption.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Yurei's initial operations indicate a focus on rapid deployment and limited scope, targeting three known victims across the specified sectors. Their operational tempo suggests cautious expansion, possibly to assess victim response before scaling activities. Notable for their use of open-source frameworks and minimal modification, Yurei may aim to refine their tactics based on early successes.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in threat actor details, based on limited observed activity. Additional analysis is recommended to identify further IOCs and understand long-term strategic goals.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics