GenieLocker is a custom cross-platform ransomware family attributed to the financially motivated Toy Ghouls threat group, also tracked as Bearlyfy, Labubu, and Laboo.boo. Active since March 2026, it has primarily targeted organizations in the Russian Federation, particularly manufacturing, as well as construction, financial services, retail, and technology. Associated intrusions have abused stolen valid credentials through trusted partner remote-access infrastructure, followed by credential theft, network discovery, lateral movement, and broad ransomware deployment using remote administration utilities.
GenieLocker has Windows PE and Linux/VMware ESXi ELF variants. The Windows variant includes anti-debugging and anti-sandbox controls, process and service termination intended to release files and inhibit backup, security, database, and virtualization services, and encryption of local and network-accessible data. It uses XChaCha20-Poly1305 for file encryption and Curve25519-XSalsa20-Poly1305 to protect per-file encryption keys. The Linux/ESXi variant supports daemonization and is designed to encrypt virtualized infrastructure; on ESXi it can stop active virtual machines and encrypt their disks. No data exfiltration, public leak site, or double-extortion activity has been observed in documented GenieLocker operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group has targeted Russian organizations since 2025 and has previously been associated with its own GenieLocker ransomware.
The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector... We discovered multiple samples of this Trojan in two variants: PE builds for Windows and ELF builds for Linux and ESXi.
The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector... We discovered multiple samples of this Trojan in two variants: PE builds for Windows and ELF builds for Linux and ESXi.
The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector... We discovered multiple samples of this Trojan in two variants: PE builds for Windows and ELF builds for Linux and ESXi.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The Linux andESXi ELF variants are simpler than their Windows counterparts, lacking both the secret argument and anti-debugging features. However, it includes options focused on ESXi, such as daemonization, worker-thread configuration, delayed execution, and a default target path of /vmfs/volumes.
Entrée via une connexion OpenVPN depuis le réseau d’un partenaire externe (exploitation d’une relation de confiance avec des identifiants volés valides)
Entrée via une connexion OpenVPN depuis le réseau d’un partenaire externe
Entrée via une connexion OpenVPN depuis le réseau d’un partenaire externe (exploitation d’une relation de confiance avec des identifiants volés valides)
Entrée via une connexion OpenVPN depuis le réseau d’un partenaire externe (exploitation d’une relation de confiance avec des identifiants volés valides)
Argument « secret » obligatoire (hex, max 4096 octets, haché en SHA-256) pour démarrer — anti-sandbox Anti-debugging : IsDebuggerPresent , CheckRemoteDebuggerPresent , thread watchdog toutes les 500ms, vérification CRC32 de la section .text
Once inside the network, the attackers deployed OpenSSH, socks5.exe, SoftPerfect Network Scanner, and Mimikatz. SoftPerfect was used to map systems
If the host name is not excluded, GenieLocker starts to kill processes that could be using the files of interest
Finally, GenieLocker starts encryption threads and searches for all available drives, including network shares, to encrypt them.
Argument « secret » obligatoire (hex, max 4096 octets, haché en SHA-256) pour démarrer — anti-sandbox Anti-debugging : IsDebuggerPresent , CheckRemoteDebuggerPresent , thread watchdog toutes les 500ms, vérification CRC32 de la section .text
The widespread deployment of the encryption Trojan was conducted with the legitimate utilities PsExec and PAExec.
They utilized PsExec and PAExec to distribute the ransomware across compromised systems.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware previously associated with Toy Ghouls; no operational details are provided in this reference.
Custom ransomware developed and used by Toy Ghouls; it is cited as part of the group's move from leaked public ransomware builders to proprietary tooling.
A custom ransomware family attributed in the content to Toy Ghouls.
Custom ransomware previously attributed to Toy Ghouls; it is mentioned as part of the group's earlier evolution toward custom tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.