Toy Ghouls Launch GenieLocker Ransomware Targeting Russian Manufacturing

Toy Ghouls Launch GenieLocker Ransomware Targeting Russian Manufacturing

First seen 30 Jul 2026, 18:51 UTC SecurelistGbhackersCybersecuritynewssecurelist.ruwww.kaspersky.com 71.5

Article Content

Browse articles
ThreatCluster

The Toy Ghouls group, also known as Bearlyfy, has introduced a new ransomware called GenieLocker, active since March 2026. This ransomware targets Windows, Linux, and VMware ESXi systems, primarily affecting the manufacturing sector in Russia. The group previously relied on third-party ransomware like LockBit and Babuk but has now developed its own custom ransomware. Attackers typically gain access through compromised OpenVPN connections, exploiting trusted relationships with partners. After breaching networks, they deploy GenieLocker using legitimate tools like PsExec and PAExec. The group has not engaged in data exfiltration or double-extortion tactics, focusing solely on file encryption. Forensic analysis indicates that they maintain a consistent modus operandi across their attacks, including lateral movement via RDP and SSH. The current status of the attacks remains active, with organizations urged to bolster their defenses against this emerging threat.

Key Points: • Toy Ghouls introduced GenieLocker ransomware, targeting Windows, Linux, and ESXi systems. • Attacks primarily affect the Russian manufacturing sector, exploiting OpenVPN connections. • The group has shifted from third-party ransomware to its own custom encryption tool.

Timeline

2026-03-01
GenieLocker ransomware first deployed
The Toy Ghouls group began using GenieLocker in attacks against Russian manufacturing organizations.
Securelist
2026-07-30
Toy Ghouls linked to new ransomware variant
Cybersecurity reports confirm Toy Ghouls' use of GenieLocker, a custom ransomware, in ongoing attacks.
Cybersecuritynews
2026-07-30
Analysis of Toy Ghouls' tactics published
A detailed analysis of the Toy Ghouls' attack methods and tools was released, highlighting their operational techniques.
Gbhackers