Analysis of Encryption Structure of Yurei Ransomware Go-based Builder
ID: 15282657-e6f4-59d1-b086-4731be2022cb
STIX ID: report--15282657-e6f4-59d1-b086-4731be2022cb
Feed Name: ASEC
Yurei is a Go-based ransomware first identified in September 2025 that targets corporate networks (reported victims in Sri Lanka and Nigeria) across industries including transportation, IT, marketing, and food & beverage; it encrypts files using ChaCha20-Poly1305, protects per-file keys via secp256k1-ECIES, deletes backups, and extorts victims through a dark-web site—this report provides technical encryption details, exclusion lists, ransom note examples, AhnLab detection names, and MD5 IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
