Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Yurei Ransomware Leverages SMB Shares and Removable Drives to Encrypt Files

Yurei Ransomware Leverages SMB Shares and Removable Drives to Encrypt Files

Posted on October 8, 2025October 8, 2025 By CWS

Yurei ransomware first emerged in early September 2025, concentrating on Home windows environments with a classy Go-based payload designed for fast, large-scale encryption.

As soon as executed, the malware enumerates all accessible native and community drives, appends a .Yurei extension to every file, and writes distinctive ransom notes in each affected listing.

Ransom Be aware (Supply – Cyfirma)

Its operators then demand fee over Tor, warning that shadow copies, backups, and log information have been irreversibly destroyed to frustrate restoration efforts.

Distributed primarily by means of stolen credentials and spear-phishing campaigns, Yurei exploits Home windows Administration Instrumentation (WMI) and credential-based distant execution to achieve a foothold in company networks.

After preliminary compromise, the binary phases itself in non permanent folders and deploys PowerShell scripts that disable Quantity Shadow Copy Service (VSS) and delete all current backups.

Cyfirma analysts famous that the ransomware’s mixture of per-file ChaCha20 encryption keys wrapped with ECIES and its self-cleaning routines make forensic investigation exceedingly tough.

Upon deployment, Yurei enters an infinite propagation loop, copying itself onto USB units as WindowsUpdate.exe and into writable SMB shares as System32Backup.exe.

This twin propagation technique permits the malware to leapfrog community segmentation controls and unfold laterally with minimal detection.

Victims report that encrypted information change into fully inaccessible, since every ChaCha20 key and nonce pair is asymmetrically wrapped with the attackers’ embedded public key and saved in a customized header separated by the ASCII marker 0x7c7c.

An infection Mechanism and Lateral Propagation

The core of Yurei’s an infection mechanism depends on PowerShell and native Home windows utilities to propagate throughout detachable and community drives.

First, it queries all volumes of sort “detachable” by way of WMI and checks for an current WindowsUpdate.exe at every root.

If absent, it copies the ransomware executable from its temp staging listing. Subsequent, it enumerates SMB shares by way of PowerShell’s Get-SmbShare cmdlet and iterates over every writable share path, utilizing Copy-Merchandise to drop System32Backup.exe.

A snippet illustrating the detachable‐media propagation routine is proven under.

# Determine 1: Detachable drive propagation utilizing PowerShell
$drives = Get-WmiObject -Class Win32_Volume | The place-Object {$_.DriveType -eq 2}
foreach ($drive in $drives) {
$path = “$($drive.DriveLetter)WindowsUpdate.exe”
if (-not (Take a look at-Path $path)) {
Copy-Merchandise -Path $MyInvocation.MyCommand.Definition -Vacation spot $path -Power
}
}

As soon as copied, Yurei spawns every dropped occasion remotely by way of a PSCredential-based CIM session or PsExec-style invocation, guaranteeing the payload executes below elevated privileges with out consumer interplay.

The script constructs a System.Administration.Automation.PSCredential object and invokes Invoke-CimMethod to create a course of on distant hosts, copying its personal binary bytes to disk earlier than execution.

By combining these stealthy propagation loops with aggressive anti-forensics—deleting VSS snapshots (vssadmin Delete Shadows /Quiet), clearing occasion logs, and overwriting its binary in reminiscence—Yurei represents a extremely automated, self-propagating menace designed for max community penetration and irreversible knowledge compromise.

Comply with us on Google Information, LinkedIn, and X to Get Extra On the spot Updates, Set CSN as a Most well-liked Supply in Google.

Cyber Security News Tags:Drives, Encrypt, Files, Leverages, Ransomware, Removable, Shares, SMB, Yurei

Post navigation

Previous Post: Google Offers Up to $20,000 in New AI Bug Bounty Program
Next Post: Google’s New AI Agent, CodeMender, Automatically Rewrites Vulnerable Code

Related Posts

Critical Cisco Firewall Vulnerability Requires Immediate Fix Critical Cisco Firewall Vulnerability Requires Immediate Fix Cyber Security News
Samba Vulnerability Enables Severe Remote Code Execution Samba Vulnerability Enables Severe Remote Code Execution Cyber Security News
HazyBeacon Exploits AWS for Covert Cyber Operations HazyBeacon Exploits AWS for Covert Cyber Operations Cyber Security News
NAKIVO v11.1 Introduces Stronger Protection for Virtual Environments NAKIVO v11.1 Introduces Stronger Protection for Virtual Environments Cyber Security News
NVIDIA Merlin Vulnerabilities Let Attackers Execute Malicious Code and Trigger DoS Condition NVIDIA Merlin Vulnerabilities Let Attackers Execute Malicious Code and Trigger DoS Condition Cyber Security News
Google Gemini Vulnerabilities Let Attackers Exfiltrate User’s Saved Data and Location Google Gemini Vulnerabilities Let Attackers Exfiltrate User’s Saved Data and Location Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark