Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Toy Ghouls’ new toy: the GenieLocker ransomware

0
Medium
Published: 07/30/2026 (07/30/2026, 09:41:18 UTC)
Source: AlienVault OTX General

Description

GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.

Technical Details

Author
AlienVault
Tlp
white
References
["https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843"]
Adversary
Toy Ghouls
Pulse Id
6a6b1c3ea08dbc663eb8f4c0
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash18f61c6d686cffd131c9fd3f3437064b
hash25480dad40152ef3d0c6d38eecc9bd9b
hash34a7f28e0bb69b0d49bacc88bdf20ac1
hash34b8828635f88078735799a3c1ac8e28
hash3a4479b51890373bfc4a011ef41fe376
hash58c0dda52b8f069660166d61fd74f911
hash5d62c1349b8981c396c9a23f4f8f053c
hash780c8f4c6f077da4da96582987920362
hash7dad78584795aa5c160520cc6accf260
hash824ca1e906cc073ee5b0f3519df69a8f
hash9201e35e2993612612919a3c71302cab
hash9969a8221312dba70dd5cbddf83a146c
hash9cd514ff2809ce0b993e3b8649e82a94
hasha50eaaf514f4f84e61ca2455a8789753
hasha8842616c9057d5cf6e1fe1fa8c3c160
hashb893eafed0659f70d4ac250f09073723
hashc68b6862725777651085650db34947fc
hashd3e06eb34d8eee7ef92cac3ad0a20ff5
hashd661cf666b9acbab7cfeae1127a261a9
hashd87d0b01d95acc936b7dc47b8f41937a
hashde3cfbb50f66079bfee20a6f64e59433
hashf08f476f26b01d142ca73923de65fc0c
hashf7b9e36e94163a9a303160945f99267a
hashfd46a80c2f45577263328984edf7f4dc

Ip

ValueDescriptionCopy
ip89.125.66.101

Threat ID: 6a6c3f149c2644c7f869d170

Added to database: 07/31/2026, 06:22:12 UTC

Last updated: 07/31/2026, 11:33:32 UTC

Views: 35

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses