Genesis is a ransomware threat actor active in 2026 that publicly claimed compromises across multiple organizations, with victim reporting concentrated in the United States and additional activity affecting Denmark and Canada. Reported victims span construction and engineering firms, information technology and staffing providers, healthcare organizations, financial services entities, real estate businesses, legal and accounting firms, and energy-related companies, indicating broad opportunistic targeting rather than a narrowly specialized victimology. Genesis is associated with ransomware intrusions that were also characterized as data-breach incidents, indicating use of data theft as part of its operations. Publicly attributed victim cases show repeated compromises of organizations in construction, technology, healthcare, financial services, and real estate. The actor has been linked to attacks against both private-sector companies and professional-services organizations. Available reporting supports classifying Genesis as a financially motivated cybercriminal actor engaged in ransomware and extortion activity. High-confidence details about Genesis beyond victim claims remain limited. The available evidence supports ransomware deployment and exfiltration-related extortion behavior, but does not reliably establish the actor's origin, specific malware lineage, affiliate structure, or deeper tradecraft such as initial access vectors, persistence mechanisms, lateral movement methods, or privilege-escalation techniques.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named in the weekly raw data as a ransomware group with 9 claimed attacks.
Conducting a ransomware attack against C.A. Walker Construction.
Conducting a ransomware attack against Boyum IT Solutions, an IT services provider in Denmark.
Conducting a ransomware attack against Infinity Pipeline,Inc.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.