logo

New Yurei Ransomware Emerges: Go-Based Variant Uses Advanced Anti-Forensics for Irreversible Double Extortion

ID: dbddcd41-ad83-5af6-90c6-44d654c1af2e

STIX ID: report--dbddcd41-ad83-5af6-90c6-44d654c1af2e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2025-10-07

Date Updated: 2026-04-22

Author: Ddos

...
...

CYFIRMA analyzes a sophisticated new double-extortion ransomware called Yurei that encrypts files with per-file ChaCha20 keys wrapped by ECIES (appending .Yurei), deletes shadow copies and logs, and uses SMB, removable drives, and credential-based remote execution (PsExec/CIM) to spread; written in Go, it includes anti-forensic self-destruct routines, drops Tor-based ransom notes targeting executives, and shows code lineage to Prince ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.