HomeSecurityYurei Ransomware Exploits SMB Shares to Encrypt Files

Yurei Ransomware Exploits SMB Shares to Encrypt Files

The Yurei ransomware first appeared in early September 2025, targeting Windows environments with a sophisticated Go-based payload designed for fast and large-scale encryption.

See also: Ransomware groups leverage remote access tools

ransomware Yurei

Once executed, the malicious software enumerates all accessible local and network drives, adds the .Yurei extension to each file, and writes unique ransom notes in every affected directory. Its operators demand payment via Tor, warning that shadow copies, backups, and log files have been irreparably destroyed to prevent recovery attempts.

The Yurei ransomware is distributed primarily through stolen credentials and spear-phishing campaigns, exploiting Windows Management Instrumentation (WMI) and credential-based remote execution to gain access to corporate networks. After the initial breach, the binary is placed in temporary folders and deploys PowerShell scripts that disable the Volume Shadow Copy Service (VSS) and delete all existing backups.

Analysts noted that the ransomware’s combination of ChaCha20 per-file encryption keys, ECIES , and self-cleaning routines make forensic investigation extremely difficult. As it grows, Yurei enters an infinite propagation loop, replicating itself to USB devices as WindowsUpdate.exe and to writable SMB shares as System32Backup.exe. This dual propagation strategy allows the malware to bypass network segmentation checks and spread laterally with minimal detection.

See also: Critical GoAnywhere vulnerability used for ransomware attacks

Yurei Ransomware Exploits SMB Shares to Encrypt Files

Victims report that the encrypted files become completely inaccessible, as each key and nonce pair for ChaCha20 is asymmetrically wrapped with the attackers' embedded public key and stored in a custom header separated by the ASCII delimiter 0x7c7c.

The core of the Yurei ransomware infection mechanism relies on PowerShell and native Windows utilities to spread to removable and network drives. First, it queries all removable volumes via WMI and checks for the presence of a WindowsUpdate.exe in each root. If it is absent, it copies the ransomware executable from its temporary staging directory. Next, it enumerates SMB shares via PowerShell’s Get-SmbShare command and iterates over each writable share path, using Copy-Item to drop System32Backup.exe .

Once copied, the Yurei ransomware launches each instance remotely via a PSCredential- or a PsExec, ensuring that the payload is executed with elevated privileges without user interaction. The script constructs a System.Management.Automation.PSCredential and calls Invoke-CimMethod to spawn a process on remote hosts, copying its own binary bytes to disk before execution.

See also: FunkLocker Ransomware Leverages AI and Windows Tools

Yurei Ransomware Exploits SMB Shares to Encrypt Files

Combining these silent propagation cycles with aggressive anti-forensic actions—deleting VSS snapshots (vssadmin Delete Shadows /Quiet), cleaning event log files and replacing its binary in memory—ransomware Yurei represents an extremely automated, self-propagating threat designed for maximum network infiltration and irreparable data destruction.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS