Securelist
Toy Ghouls Launch GenieLocker Ransomware Targeting Russian Manufacturing
Article Content
The Toy Ghouls group, also known as Bearlyfy, has introduced a new ransomware called GenieLocker, active since March 2026. This ransomware targets Windows, Linux, and VMware ESXi systems, primarily affecting the manufacturing sector in Russia. The group previously relied on third-party ransomware like LockBit and Babuk but has now developed its own custom ransomware. Attackers typically gain access through compromised OpenVPN connections, exploiting trusted relationships with partners. After breaching networks, they deploy GenieLocker using legitimate tools like PsExec and PAExec. The group has not engaged in data exfiltration or double-extortion tactics, focusing solely on file encryption. Forensic analysis indicates that they maintain a consistent modus operandi across their attacks, including lateral movement via RDP and SSH. The current status of the attacks remains active, with organizations urged to bolster their defenses against this emerging threat.
Key Points: • Toy Ghouls introduced GenieLocker ransomware, targeting Windows, Linux, and ESXi systems. • Attacks primarily affect the Russian manufacturing sector, exploiting OpenVPN connections. • The group has shifted from third-party ransomware to its own custom encryption tool.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.