Skip to content
Toy Ghouls Launch GenieLocker Ransomware Targeting Russian Manufacturing

Toy Ghouls Launch GenieLocker Ransomware Targeting Russian Manufacturing

First seen 30 Jul 2026, 18:51 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 30, 2026 at 22:28 UTC

The Toy Ghouls group, also known as Bearlyfy, has introduced a new ransomware called GenieLocker, active since March 2026. This ransomware targets Windows, Linux, and VMware ESXi systems, primarily affecting the manufacturing sector in Russia. The group previously relied on third-party ransomware like LockBit and Babuk but has now developed its own custom ransomware. Attackers typically gain access through compromised OpenVPN connections, exploiting trusted relationships with partners. After breaching networks, they deploy GenieLocker using legitimate tools like PsExec and PAExec. The group has not engaged in data exfiltration or double-extortion tactics, focusing solely on file encryption. Forensic analysis indicates that they maintain a consistent modus operandi across their attacks, including lateral movement via RDP and SSH. The current status of the attacks remains active, with organizations urged to bolster their defenses against this emerging threat.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 53d ago How this analysis works

Timeline

2026-03-01
GenieLocker ransomware first deployed
The Toy Ghouls group began using GenieLocker in attacks against Russian manufacturing organizations.
Securelist
2026-07-30
Toy Ghouls linked to new ransomware variant
Cybersecurity reports confirm Toy Ghouls' use of GenieLocker, a custom ransomware, in ongoing attacks.
Cybersecuritynews
2026-07-30
Analysis of Toy Ghouls' tactics published
A detailed analysis of the Toy Ghouls' attack methods and tools was released, highlighting their operational techniques.
Gbhackers

More articles in this cluster (5)

Following this threat?

Track Head Mare, Toy Ghouls and GenieLocker in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed