yurei
First seen September 5, 2025Active3 claimed victims
The claims below are reproduced as posted by yurei on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| noblecorp.net | September 9, 2025 | ransomware_live | — |
| www.thepromisenig.com | September 8, 2025 | ransomware_live | — |
| www.midcity.lk | September 5, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).