All ransomware groups
yurei
3 tracked victims
·first seen 2025-09-05·last activity 2025-09-09Group profile
Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.
Recent victims
| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2025-09-09 | noblecorp.netnoblecorp.net | Energy | CH |
| 2025-09-08 | www.thepromisenig.comwww.thepromisenig.com | Consumer Services | NG |
| 2025-09-05 | www.midcity.lkwww.midcity.lk | Agriculture and Food Production | LK |

