Yurei is a ransomware family observed in 2025 that encrypts victim data and appends a distinctive extension to affected files while dropping a ransom note identifying the operation as Yurei. The note indicates a double-extortion model, claiming that attackers compromised part or all of a victim organization’s internal infrastructure, exfiltrated corporate data prior to encryption, and destroyed accessible backups to increase pressure on the victim. It also offers test decryption, requests information about cyber-insurance coverage, and states that ransom demands may be tailored after assessing the victim’s finances.
Yurei targets common business-relevant file types, including documents, databases, archives, media, and disk images. Available reporting indicates low observed prevalence and suggests the operation was newly emerging at the time it was documented. The ransomware has been associated with Tor-based negotiation infrastructure and appears intended for broad victimization rather than a narrowly defined geography, with English-language extortion messaging indicating likely targeting of English-speaking organizations.
Reported intrusion vectors are varied and consistent with common ransomware deployment patterns, including exposed or weakly secured remote access services, phishing or spam-delivered malicious attachments, exploit-based compromise, deceptive downloads, fake updates, malvertising, botnet-assisted delivery, and trojanized installers. These distribution paths are assessed as possible delivery mechanisms rather than all being individually confirmed in live intrusions. No specific threat actor attribution is established with high confidence beyond the ransomware operation name itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a prior Japanese-themed ransomware group for comparison/background.
Minimal-activity ransomware brand referenced as part of the long-tail of operators.
Yurei is a new ransomware strain written in Go, designed to encrypt files and demand payment for decryption.
Ransomware that encrypts user and corporate data, appends the .Yurei extension, drops a ransom note named _README_Yurei.txt, claims backup deletion and data exfiltration, and demands payment for decryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.