216.73.216.6

YUREI RANSOMWARE: THE DIGITAL GHOST

· Published 04/10/2025 09:22 · Modified 06/10/2025 08:03

Export JSON

Essential information

Published
04/10/2025 09:22
Modified
06/10/2025 08:03
Tags
2025-10-04 double-extortion ransomware yurei
Related entities
14 techniques (mitre), 1 malware, 5 others

Description

A sophisticated family called has emerged, targeting Windows systems with advanced encryption methods. It rapidly encrypts data using ChaCha20 and ECIES, appends . to files, and disables recovery options. The malware spreads via SMB shares, removable drives, and credential-based remote execution. It employs anti-forensics techniques, including log wiping and secure deletion. features capabilities, threatening data leaks alongside ransom demands. Analysis suggests possible code reuse from the Prince . The 's professional build, stealthy propagation, and high operational speed make it a significant threat designed for irreversible data compromise.

External references