216.73.217.22

Yurei the New Ransomware Group on the Scene

· Published 12/09/2025 15:33 · Modified 15/09/2025 19:04

Export JSON

Essential information

Published
12/09/2025 15:33
Modified
15/09/2025 19:04
Tags
2025-09-12 double-extortion go morocco open-source prince ransomware ransomware satanlockv2 shadow copies yurei
Related entities
5 observables, 1 intrusion sets (apt), 8 techniques (mitre), 3 malware, 5 others

Description

, a newly emerged group, targeted a Sri Lankan food manufacturing company on September 5, 2025. The group employs a model, encrypting files and exfiltrating sensitive data. Check Point Research discovered that 's is based on the Prince-, with minor modifications. The , written in , contains a flaw allowing partial recovery through . Since its first victim, has quickly expanded to three victims across Sri Lanka, India, and Nigeria. The investigation suggests the threat actor may originate from . 's operation demonstrates how malware lowers the entry barrier for cybercriminals, enabling less-skilled actors to launch attacks.

External references