Ransomware Group intelligence
Yurei
InactiveTrack Yurei with 3 published victims and 1 known leak locations in a single intelligence view.
Overview
Yurei is tracked by Breach House as a ransomware group with 3 published victims.
Sri Lanka is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 3h ago | fewcriet5rhoy66k6c4cyvb2pqrblxtx4mekj3s5l4jjt4t4kn4vheyd.onion |
Top Activity Sectors (3)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Yurei, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: yurei executes malicious PowerShell scripts to stage ransomware payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: yurei leverages native API calls to interact with Windows services and disable security tools.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: yurei modifies registry run keys to ensure ransomware execution upon system reboot.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: yurei disables antivirus and monitoring tools by terminating processes and modifying security configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: yurei deletes Volume Shadow Copies and backup files to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: yurei spreads laterally via SMB/Windows Admin Shares to compromise additional networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1048 Exfiltration Over Alternative Protocol Exfiltration
What they do: yurei encrypts victim files using symmetric cryptography keys derived from victim data.
What that means: Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: yurei exfiltrates sensitive victim data before encryption to increase ransom pressure.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: yurei encrypts victim files using custom ransomware binaries, targeting documents and system data for impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: yurei calls system recovery inhibitors like vssadmin to disable Volume Shadow Copy restoration.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (16)
▼Software Yurei has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery
Discovery & enumeration
LOLBAS (living-off-the-land binaries)
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Victims (3)
Search, filter and paginate the victim timeline for Yurei. Showing 1–3 of 3.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | noblecorp.net id22193 View details | Switzerland | Manufacturing / Engineering | ||
|
Noble Corporation is a leading industrial insulation and materials supply company based in India, renowned for its expertise, innovation, and dedication to quality. Established in 1935, the company has steadily expanded its presence across the country, earning a strong reputation as one of the most trusted providers of insulation solutions for commercial, industrial, and infrastructure projects. From thermal and acoustic insulation to complex industrial pipe and equipment solutions, Noble Corp has become a household name among India’s manufacturing, construction, and energy sectors. |
|||||
| Ransomware | www.thepromisenig.com id22181 View details | Nigeria | Communication / Marketing | ||
|
The Promise Nigeria Ltd is a leading brand in Nigeria’s fast-food and catering industry, renowned for its dedication to quality, freshness, and customer satisfaction. Established in 2000 and incorporated in 2003, the company has steadily expanded its presence, earning a strong reputation as one of the most trusted names in quick service dining and integrated catering solutions. From freshly prepared meals to large-scale corporate catering, The Promise has become a household name across Port Harcourt and beyond. |
|||||
| Ransomware | www.midcity.lk id22151 View details | Sri Lanka | Public Sector | ||
|
Midcity Marketing (Pvt) Ltd, Sri Lanka is a dominant force in the import, distribution, and marketing of essential dry food commodities. Since its establishment in 1995, the company has built a reputation based on transparency, integrity, and trust, creating one of the most extensive supply chains in Sri Lanka. It imports vast quantities of onions, potatoes, garlic, rice, and mandarins, and at the same time exports premium-grade black pepper to major markets such as India, Pakistan, and Bangladesh. |
|||||