Uptime Hamster: 10d 9h 49mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza yurei

yurei

2 incidentes 2 paises 1 sectores ransomware MA Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Yurei emerged as a ransomware group on September 5, 2025, operating a double-extortion model where they encrypt victim files and exfiltrate sensitive data to demand ransom. The group is assessed with moderate confidence to be of Moroccan origin, based on early malware submissions. Yurei distinguishes itself by leveraging a minimally modified, open-source ransomware codebase, Prince-Ransomware, which allows even less-skilled threat actors to conduct operations. A key characteristic is its initial oversight in failing to delete Volume Shadow Copies, a common ransomware technique, though later reports indicate the use of tools like SDelete for this purpose, alongside deploying "Stranger Things" themed tooling.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: Yurei
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: Yurei
DLS / leak siteunknownwww.team-cymru.comBushidoUK ToolMatrix GroupProfiles: Yurei
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: yurei
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1) Nigeria (1)

Paises objetivo (SOCRadar)

SwitzerlandIndiaSri LankaNigeriaUnited States

Sectores atacados

Manufacturing (1)

Sectores objetivo (SOCRadar)

Energy & Utilities ConstructionManufacturingWholesale TradeTransportation&WarehousingInformation ServicesProfessional&Technical ServicesHealthCare & Social AssistanceAccommodation&Food ServicesOther

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com