A new ransomware strain named Yurei has emerged, targeting Windows systems with a Go-based architecture and employing advanced anti-forensics techniques to facilitate irreversible double extortion attacks. Security researchers have observed that Yurei ransomware leverages the ChaCha20 encryption algorithm to rapidly encrypt files on compromised systems, making data recovery without the decryption key virtually impossible. The malware executes PowerShell commands to delete Volume Shadow Copies, backup catalogs, Windows event logs, and system logs, thereby hindering forensic investigations and preventing restoration from backups. Yurei’s infection chain includes the creation of CIM sessions and PSCredential objects, which are used to conduct remote execution and enable lateral movement within the victim’s network. The ransomware actively enumerates writable SMB shares, allowing it to self-propagate across networked systems and maximize its impact. After spreading, Yurei executes secureDelete, cleanTraces, and wipeMemory functions to further erase evidence of its activities and ensure that encrypted data cannot be recovered. The ransomware was first observed in an attack against a food manufacturer in Sri Lanka, indicating that it is already being used in real-world intrusions. Analysts have noted that Yurei shares similarities with the open-source Prince ransomware, particularly in its Go binary structure and encryption methods, but it distinguishes itself through enhancements such as parallel encryption and more robust anti-forensics measures. The use of modified open-source ransomware kits like Yurei highlights a growing trend among cybercriminals to adapt and improve existing tools for more effective attacks. The irreversible nature of Yurei’s double extortion approach means that victims face both the threat of data loss and the risk of sensitive information being leaked if ransom demands are not met. Security experts warn that the advanced anti-forensics capabilities of Yurei make detection and response significantly more challenging for defenders. Organizations are advised to strengthen their backup strategies, monitor for unusual PowerShell activity, and restrict access to SMB shares to mitigate the risk of infection. The emergence of Yurei underscores the evolving sophistication of ransomware threats and the need for continuous vigilance in cybersecurity defenses. Incident response teams should be prepared for the possibility of rapid lateral movement and data destruction in the event of a Yurei infection. The ransomware’s ability to wipe memory and traces after execution further complicates post-incident analysis and recovery efforts. As Yurei continues to be deployed in targeted attacks, it is likely to inspire further innovation among ransomware developers seeking to evade detection and maximize extortion profits.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Security researchers publicly reported a new Yurei ransomware variant written in Go that targets Windows environments. The reporting said the malware uses advanced anti-forensics and supports double-extortion tactics intended to make recovery more difficult.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourceid-ransomware.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.