A newly identified ransomware group, named Yurei, has emerged on the cybercrime landscape, with its first reported victim on September 5.
According to Check Point Research, the group targeted a Sri Lankan food manufacturing company as its initial case before expanding with additional victims from India and Nigeria in quick succession.
The operators follow a double-extortion model, encrypting victims’ data while also exfiltrating sensitive files for leverage in ransom negotiations.
Technical Analysis of Yurei Ransomware
Yurei ransomware is developed in the Go programming language and heavily borrows from Prince-Ransomware, an open-source project available on GitHub.
Researchers highlighted that the developers failed to strip debug symbols and module names from their compiled binaries, leaving traces that confirmed much of the source code was reused.
This shortcut highlights how open-source malware reduces the barriers for less skilled actors to initiate ransomware campaigns with minimal technical expertise.
The ransomware encrypts files using the ChaCha20 cipher, generating a unique key and nonce for each file. Keys are subsequently encrypted with ECIES and stored alongside the encrypted data, with files appended with the .Yurei extension.
A notable improvement from Prince-Ransomware is Yurei’s use of Go’s concurrency model (goroutines) to encrypt drives in parallel, significantly improving encryption speed.
In addition, the malware monitors attached network drives and automatically includes them in encryption attempts. Despite these enhancements, Yurei inherits critical flaws from its predecessor.
Most importantly, the ransomware does not remove Volume Shadow Copies, a neglected step that allows victims with VSS enabled to potentially restore previous snapshots without paying a ransom.
While this mitigates the impact on operational recovery, the extortion risk remains, as the group prioritizes the threat of data leakage.
PowerShell Automation and Attacker Infrastructure
Yurei employs PowerShell scripts to attempt to set a new desktop background, mimicking techniques observed in other ransomware families. The malware contains commands to download and set a ransom wallpaper.
However, due to a missing URL, the wallpaper reverts to a blank background, exposing the low level of refinement in its development. This reliance on unaltered PowerShell automation underscores the threat actors’ dependency on copy-pasted code from the Prince-Ransomware repository.
The ransom note, dropped as “_README_Yurei.txt,” instructs victims to use an .onion portal for negotiations. Attackers promise to provide decryption keys upon payment and even claim to offer a security report detailing the vulnerabilities they exploited.
Such tactics demonstrate how ransomware operators increasingly mimic penetration-testing services, blurring the lines between crime, extortion, and pseudo-consulting.
Indicators suggest the ransomware group may have origins in Morocco, supported by VirusTotal submissions and Arabic code comments found within their darknet portal. The group’s infrastructure further reveals ties to previously identified Prince-Ransomware spin-offs such as SatanLockv2.
Yurei highlights the evolving ransomware ecosystem where open-source code, minimal technical knowledge, and aggressive extortion tactics combine to create potent threats capable of rapidly compromising global targets.
Indicators of Compromise
| Description | Value |
|---|---|
| Onion Page | fewcriet5rhoy66k6c4cyvb2pqrblxtx4mekj3s5l4jjt4t4kn4vheyd.onion |
| Yurei Ransomware | 49c720758b8a87e42829ffb38a0d7fe2a8c36dc3007abfabbea76155185d2902 4f88d3977a24fb160fc3ba69821287a197ae9b04493d705dc2fe939442ba6461 1ea37e077e6b2463b8440065d5110377e2b4b4283ce9849ac5efad6d664a8e9e 10700ee5caad40e74809921e11b7e3f2330521266c822ca4d21e14b22ef08e1d 89a54d3a38d2364784368a40ab228403f1f1c1926892fe8355aa29d00eb36819 f5e122b60390bdcc1a17a24cce0cbca68475ad5abee6b211b5be2dea966c2634 0303f89829763e734b1f9d4f46671e59bfaa1be5d8ec84d35a203efbfcb9bb15 |
| SatanLockV2 Ransomware | afa927ca549aaba66867f21fc4a5d653884c349f8736ecc5be3620577cf9981f d2539173bdc81503bf1b842a21d9599948e957cadc76a283a52f5849323d8e04 |
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates