Skip to content

Yurei

Yurei is a ransomware family observed in 2025 that encrypts victim data and appends a distinctive extension to affected files while dropping a ransom note identifying the operation as Yurei.

Profile source: Mallory opens in a new tab

Yurei

Family profile

Yurei is a ransomware family observed in 2025 that encrypts victim data and appends a distinctive extension to affected files while dropping a ransom note identifying the operation as Yurei. The note indicates a double-extortion model, claiming that attackers compromised part or all of a victim organization’s internal infrastructure, exfiltrated corporate data prior to encryption, and destroyed accessible backups to increase pressure on the victim. It also offers test decryption, requests information about cyber-insurance coverage, and states that ransom demands may be tailored after assessing the victim’s finances.

Yurei targets common business-relevant file types, including documents, databases, archives, media, and disk images. Available reporting indicates low observed prevalence and suggests the operation was newly emerging at the time it was documented. The ransomware has been associated with Tor-based negotiation infrastructure and appears intended for broad victimization rather than a narrowly defined geography, with English-language extortion messaging indicating likely targeting of English-speaking organizations.

Reported intrusion vectors are varied and consistent with common ransomware deployment patterns, including exposed or weakly secured remote access services, phishing or spam-delivered malicious attachments, exploit-based compromise, deceptive downloads, fake updates, malvertising, botnet-assisted delivery, and trojanized installers. These distribution paths are assessed as possible delivery mechanisms rather than all being individually confirmed in live intrusions. No specific threat actor attribution is established with high confidence beyond the ransomware operation name itself.

Capabilities

  • Exfiltration
  • Extortion

Operational record

1
YARA rules
1
Leak sites
0 available

Discovery Enum

  • Everything.exe
  • SoftPerfect NetScan

LOLBAS

  • PsExec
  • SDelete

Offsec

  • Invoke-TheHash
  • NetExec
  • Rubeus
  • WinPEAS

RMM Tools

  • AnyDesk

MITRE ATT&CK

Yurei in ATT&CK

9 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.