Securelist
GenieLocker Ransomware Targets Russian Manufacturing Sector
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The GenieLocker ransomware, attributed to the Toy Ghouls group, has been active since March 2026, primarily targeting organizations in the Russian manufacturing sector. This custom ransomware encrypts systems running Windows, Linux, and VMware ESXi. Attackers gained initial access through an OpenVPN connection from a partner's network, exploiting stolen credentials. They deployed additional tools such as OpenSSH and Mimikatz for lateral movement and credential dumping. The ransomware was executed using legitimate utilities like PsExec and PAExec, encrypting files on compromised systems. Forensic analysis revealed no data exfiltration, consistent with the group's previous tactics. The Windows version of GenieLocker is primarily written in C and compiled with C++ libraries. The threat remains active with no reported mitigation strategies from affected organizations.
Key Points: • GenieLocker ransomware is a custom strain linked to the Toy Ghouls group. • The ransomware targets Windows, Linux, and VMware ESXi systems, focusing on Russian manufacturers. • Attackers exploited trusted relationships and used tools like Mimikatz for credential access.