Yurei Ransomware Uses Common Tools, Adds Stranger Things References
ID: a35eb8da-75e6-5944-8743-4888f96a5778
STIX ID: report--a35eb8da-75e6-5944-8743-4888f96a5778
Feed Name: HackRead
Team Cymru observed a Yurei ransomware extortion campaign that leverages a modular, show-themed toolkit (Vecna.ps1, StrangerThings.exe) built on Prince Ransomware; operators obtain access via stolen credentials, map networks with NetScan/NetExec, escalate privileges with Rubeus, maintain persistence with AnyDesk, and disable defenses and backups using FixingIssues2.ps1 and SDelete. The campaign, active since late 2025 and monitored through NetFlow and PsExec, has a small number of publicly listed victims but demonstrates easy-to-assemble toolkits that lower the barrier to cybercrime.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
