yurei
Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.
| Name | Country | Sector | Date |
|---|---|---|---|
| noblecorp.net | CH | Energy | 2025-09-09T11:23:14.819818+00:00 |
| www.thepromisenig.com | NG | Consumer Services | 2025-09-08T15:45:38.313765+00:00 |
| www.midcity.lk | LK | Agriculture and Food Production | 2025-09-05T19:35:05.078000+00:00 |
Data from ransomware.live