HomeSecurityNew Yurei Ransomware Encrypts Files with ChaCha20

New Yurei Ransomware Encrypts Files with ChaCha20

Yurei ransomware, which appeared in early September 2025, has quickly attracted attention due to its innovative combination of Go- based execution and ChaCha20 encryption algorithm .

See also: CyberVolk ransomware targets critical infrastructure

Yurei Ransomware

It was first recorded on September 5th when a food manufacturer in Sri Lanka fell victim. The perpetrator behind the Yurei ransomware adopted a dual extortion model: encrypting files while extracting sensitive data for additional pressure. Within days, two more victims in India and Nigeria were publicly recorded, highlighting the operator’s rapid expansion.

Unlike many sophisticated groups that develop custom tools, the Yurei Ransomware codebase is located in the open source Prince-Ransomware, raising questions about the skill level and resources of the attackers. At its core, Yurei leverages Go’s concurrent execution features to enumerate all disks in parallel and encrypt files using the ChaCha20 algorithm. For each file, a new random key and ChaCha20 nonce, which are then encrypted using ECIES with the attacker’s public key. The resulting ciphertext, key, and nonce are concatenated with separators.

Check Point researchers noted that Yurei retains symbols in the binary, a flaw inherited from the Prince-Ransomware creator, who did not remove debugging information. This omission provided analysts with clear function names such as Yurei_encryption_generateKey and Yurei_filewalker_EncryptAllDrivesAndNetwork , making reverse engineering easier.

See also: The Gentlemen ransomware: Meet the new threat

New Yurei Ransomware Encrypts Files with ChaCha20

However, Yurei ransomware's use of Go complicates detection for some older antivirus, showing how language selection can affect defense measures. After successful encryption, Yurei attempts to set a custom wallpaper via PowerShell, although the absence of a valid URL causes the command to fail, resulting in a blank background.

In the context of defensive strategies, the failure of Yurei ransomware to remove Volume Shadow Copies reveals a critical weakness. Organizations with VSS enabled can recover files without paying a ransom, although the leaked data remains at risk. The combination of rapid encryption, data extraction, and incomplete persistence techniques reflects a low-effort but effective operation.

See also: The mastermind of major ransomware attacks is in the US's sights

New Yurei Ransomware Encrypts Files with ChaCha20

As Yurei continues to target various domains, security teams are urged to monitor for the distinctive .Yurei, enforce strict exit controls, and validate VSS snapshots to mitigate the impact of this emerging threat.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS