A new ransomware operator has emerged that relies on open source malware to launch double-extortion attacks that have claimed several victims. The group operates using an only slightly modified version of the Prince-Ransomware binary, an open source ransomware family available on GitHub. It maintains a blog to list its ransomware victims and show proof that they've been compromised, and it provides a secure chat interface for negotiations with victims. "Ransomware usually targets and deletes these copies to block victims from using Windows' built-in recovery options," according to Check Point. Since the Yurei ransomware doesn't include this functionality, if the shadow copies are enabled, victims can restore their files to a previous snapshot without having to negotiate with Yurei, according to the post.