New Yurei Ransomware Emerges: Go-Based Variant Uses Advanced Anti-Forensics for Irreversible Double Extortion
ID: dbddcd41-ad83-5af6-90c6-44d654c1af2e
STIX ID: report--dbddcd41-ad83-5af6-90c6-44d654c1af2e
Feed Name: securityonline.info
Threat Score
CYFIRMA analyzes a sophisticated new double-extortion ransomware called Yurei that encrypts files with per-file ChaCha20 keys wrapped by ECIES (appending .Yurei), deletes shadow copies and logs, and uses SMB, removable drives, and credential-based remote execution (PsExec/CIM) to spread; written in Go, it includes anti-forensic self-destruct routines, drops Tor-based ransom notes targeting executives, and shows code lineage to Prince ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
