Ransomware group profile · #286 by claimed victims
Yurei ransomware
Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.
Victimology
Who Yurei claims to have breached, from 3 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 3 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| noblecorp.net noblecorp.net | Energy & Utilities | CH | 9 Sep 2025 |
| www.thepromisenig.com thepromisenig.com | Retail & E-Commerce | NG | 8 Sep 2025 |
| www.midcity.lk midcity.lk | Agriculture and Food Production | LK | 5 Sep 2025 |
All 3 Yurei victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Yurei is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Yurei ransomware still active?
How many victims has Yurei claimed?
Which industries does Yurei target?
Which countries are most affected by Yurei?
Where does VULONE get Yurei victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].