yurei
2 incidentes
2 paises
1 sectores
ransomware MA Ultimo: 2026-06-29
Yurei emerged as a ransomware group on September 5, 2025, operating a double-extortion model where they encrypt victim files and exfiltrate sensitive data to demand ransom. The group is assessed with moderate confidence to be of Moroccan origin, based on early malware submissions. Yurei distinguishes itself by leveraging a minimally modified, open-source ransomware codebase, Prince-Ransomware, which allows even less-skilled threat actors to conduct operations. A key characteristic is its initial oversight in failing to delete Volume Shadow Copies, a common ransomware technique, though later reports indicate the use of tools like SDelete for this purpose, alongside deploying "Stranger Things" themed tooling.
Canales, DLS e infraestructura asociada
Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.
| Tipo | Estado | Host / enlace | Title / ultimo titulo |
| Repositorio | unknown | github.com | BushidoUK ToolMatrix GroupProfiles: Yurei |
| Repositorio | unknown | github.com | BushidoUK ToolMatrix GroupProfiles: Yurei |
| DLS / leak site | unknown | www.team-cymru.com | BushidoUK ToolMatrix GroupProfiles: Yurei |
| DLS / leak site | unknown | ransomware.anggipradana.com | Ransomware Group: yurei |
Paises objetivo (SOCRadar)
Switzerland
India
Sri Lanka
Nigeria
United States
Sectores atacados
Manufacturing (1)
Sectores objetivo (SOCRadar)
Energy & Utilities ConstructionManufacturingWholesale TradeTransportation&WarehousingInformation ServicesProfessional&Technical ServicesHealthCare & Social AssistanceAccommodation&Food ServicesOther
URLs nuevas detectadas en IntelTracker