Skip to content

Yurei

Yurei is a Go-based ransomware family targeting Windows systems, first identified in September 2025.

Yurei

Family profile

Yurei is a Go-based ransomware family targeting Windows systems, first identified in September 2025. Its first reported victim was a food manufacturing company in Sri Lanka. It encrypts files on accessible local drives and network shares using unique per-file ChaCha20 keys and nonces, with key material protected through ECIES using an embedded attacker public key. Chunked file processing and parallel encryption using Go goroutines enable it to process large files without loading their entire contents into memory.

Yurei propagates by copying itself to writable SMB shares and removable drives. It also supports credential-based remote execution through PowerShell and CIM sessions, transferring and executing payloads on remote hosts. A recurring propagation routine continues attempting removable-media and network-share distribution while the malware remains running. Payload copies masquerade as legitimate Windows components.

Its defense-evasion and anti-forensic behavior includes deleting backup catalogs, removing Windows logs, manipulating file creation timestamps, and attempting to erase its executable and sensitive memory artifacts. Its self-deletion routine uses repeated overwrites and renaming before deletion. Yurei also changes the desktop wallpaper and places ransom notes in affected directories. The notes direct victims to Tor-based negotiations, offer test decryption, and threaten publication of allegedly stolen corporate data. Successful data exfiltration has not been independently established. No confirmed attribution to a separate threat actor or geographic origin is available.

Capabilities

  • Defense Evasion
  • Extortion
  • Lateral Movement

Samples

Recent samples

2 sandbox samples in the Derp library, newest 2 shown

MITRE ATT&CK

Yurei in ATT&CK

9 distinct techniques