GenieLocker Ransomware Targets Russian Manufacturing Sector

GenieLocker Ransomware Targets Russian Manufacturing Sector

First seen 30 Jul 2026, 18:51 UTC SecurelistGbhackers 83% similarity 70.5

Article Content

Browse articles
ThreatCluster

The GenieLocker ransomware, attributed to the Toy Ghouls group, has been active since March 2026, primarily targeting organizations in the Russian manufacturing sector. This custom ransomware encrypts systems running Windows, Linux, and VMware ESXi. Attackers gained initial access through an OpenVPN connection from a partner's network, exploiting stolen credentials. They deployed additional tools such as OpenSSH and Mimikatz for lateral movement and credential dumping. The ransomware was executed using legitimate utilities like PsExec and PAExec, encrypting files on compromised systems. Forensic analysis revealed no data exfiltration, consistent with the group's previous tactics. The Windows version of GenieLocker is primarily written in C and compiled with C++ libraries. The threat remains active with no reported mitigation strategies from affected organizations.

Key Points: • GenieLocker ransomware is a custom strain linked to the Toy Ghouls group. • The ransomware targets Windows, Linux, and VMware ESXi systems, focusing on Russian manufacturers. • Attackers exploited trusted relationships and used tools like Mimikatz for credential access.

ThreatCluster AI How this analysis works

Timeline

2026-03-31
GenieLocker ransomware deployed
Attackers accessed a manufacturing network via an OpenVPN connection using stolen credentials, deploying GenieLocker ransomware.
Securelist
2026-07-30
GenieLocker ransomware detailed
Securelist published a comprehensive analysis of GenieLocker, outlining its capabilities and attack methods.
Securelist
2026-07-30
Gbhackers report on GenieLocker
Gbhackers confirmed GenieLocker's encryption capabilities across multiple platforms and its focus on Russian industries.
Gbhackers

Community

Browse all →