Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Yurei

Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.

Victims
3
 
First Discovered
2025-09-05
victim
Last Discovered
2025-09-09
victim
Inactive Since
332
days
Avg Delay
N/A
attack→claim
Infostealer
0.0%
victims with domain
Countries
3
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Yurei Blog No 2026-04-28T07:23:48 fewcriet5rhoy66k6c4cyvb2pqrblxtx4mekj3s5l4jjt4t4kn4vheyd.onion

Target
Top 5 Activity Sectors
  • Energy & Utilities 1
  • Retail & E-Commerce 1
  • Agriculture and Food Production 1
Top 5 Countries
  • CH flag Switzerland 1
  • NG flag Nigeria 1
  • LK flag Sri Lanka 1

Heatmap

Tools Used
This information is provided by Ransomware-Tool-Matrix
Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
Everything.exe

SoftPerfect NetScan


AnyDesk









Invoke-TheHash

NetExec

Rubeus

WinPEAS



PsExec

SDelete






YARA Rules (1)

Victims (3)
Logo
Discovered: 2025-09-09 (11mo ago)
Noble Corporation is a leading industrial insulation and materials supply company based in India, re…
Logo
Discovered: 2025-09-08 (11mo ago)
The Promise Nigeria Ltd is a leading brand in Nigeria’s fast-food and catering industry, renowned fo…
Logo
Discovered: 2025-09-05 (11mo ago)
Midcity Marketing (Pvt) Ltd, Sri Lanka is a dominant force in the import, distribution, and marketin…