Yurei Ransomware First Victims Identified
Summary
Hide β²
Show βΌ
Yurei ransomware, first observed on September 5, 2025, has claimed its first victims. The ransomware is based on the open-source Prince-Ransomware binary and has a flaw that allows victims to recover data using Windows' Volume Shadow Copy Service (VSS). The group has targeted a food manufacturing company in Sri Lanka and two other entities in India and Nigeria. The ransomware operators are believed to be based in Morocco. Yurei ransomware is written in Go, making it challenging for some antivirus tools to detect. The group uses double-extortion tactics, encrypting systems and stealing data for extortion. Despite its flaws, the ransomware has already seen some success due to the fear of data leakage.
Timeline
-
16.09.2025 11:53 π° 1 articles Β· β± 1d ago
Yurei Ransomware First Victims Identified
Yurei ransomware, first observed on September 5, 2025, has claimed its first victims. The ransomware is based on the open-source Prince-Ransomware binary and has a flaw that allows victims to recover data using Windows' Volume Shadow Copy Service (VSS). The group has targeted a food manufacturing company in Sri Lanka and two other entities in India and Nigeria. The ransomware operators are believed to be based in Morocco. The ransomware is written in Go, making it challenging for some antivirus tools to detect. The group uses double-extortion tactics, encrypting systems and stealing data for extortion. Despite its flaws, the ransomware has already seen some success due to the fear of data leakage.
Show sources
- Emerging Yurei Ransomware Claims First Victims β www.darkreading.com β 16.09.2025 11:53
Information Snippets
-
Yurei ransomware was first observed on September 5, 2025.
First reported: 16.09.2025 11:53π° 1 source, 1 articleShow sources
- Emerging Yurei Ransomware Claims First Victims β www.darkreading.com β 16.09.2025 11:53
-
The first victim identified was MidCity Marketing, a food manufacturing company in Sri Lanka.
First reported: 16.09.2025 11:53π° 1 source, 1 articleShow sources
- Emerging Yurei Ransomware Claims First Victims β www.darkreading.com β 16.09.2025 11:53
-
Two additional victims were identified in India and Nigeria by September 9, 2025.
First reported: 16.09.2025 11:53π° 1 source, 1 articleShow sources
- Emerging Yurei Ransomware Claims First Victims β www.darkreading.com β 16.09.2025 11:53
-
Yurei ransomware is based on the open-source Prince-Ransomware binary, written in Go.
First reported: 16.09.2025 11:53π° 1 source, 1 articleShow sources
- Emerging Yurei Ransomware Claims First Victims β www.darkreading.com β 16.09.2025 11:53
-
The ransomware does not delete shadow copies generated by Windows' Volume Shadow Copy Service (VSS), allowing victims to recover data.
First reported: 16.09.2025 11:53π° 1 source, 1 articleShow sources
- Emerging Yurei Ransomware Claims First Victims β www.darkreading.com β 16.09.2025 11:53
-
The ransomware operators are believed to be based in Morocco.
First reported: 16.09.2025 11:53π° 1 source, 1 articleShow sources
- Emerging Yurei Ransomware Claims First Victims β www.darkreading.com β 16.09.2025 11:53
-
Yurei ransomware uses double-extortion tactics, encrypting systems and stealing data for extortion.
First reported: 16.09.2025 11:53π° 1 source, 1 articleShow sources
- Emerging Yurei Ransomware Claims First Victims β www.darkreading.com β 16.09.2025 11:53