Toy Ghouls’ new toy: the GenieLocker ransomware
GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.
AI Analysis
Technical Summary
GenieLocker is a custom ransomware family operated by the Toy Ghouls group, active since March 2026 and targeting organizations mainly in Russia's manufacturing sector. Unlike their prior use of third-party ransomware like RedAlert, LockBit, and Babuk, GenieLocker is a bespoke malware with two variants: PE for Windows and ELF for Linux/ESXi. The Windows variant includes advanced features such as process termination, service shutdown, anti-debugging, and encryption using libsodium's XChaCha20-Poly1305 algorithm. The attack chain typically begins with compromised VPN credentials from trusted partners, enabling initial access. The group then uses tools like Mimikatz for credential harvesting, SoftPerfect Network Scanner, and SSH utilities for lateral movement, deploying ransomware with PsExec and PAExec.
Potential Impact
Successful exploitation results in encryption of critical systems in targeted organizations, disrupting operations primarily in manufacturing within the Russian Federation. The ransomware's advanced encryption and evasion techniques complicate detection and remediation. The use of compromised VPN credentials and credential theft tools increases the risk of widespread network compromise and lateral movement before ransomware deployment.
Mitigation Recommendations
No official patch or fix is available as this is malware rather than a software vulnerability. Organizations should focus on securing VPN credentials, monitoring for unauthorized access, and restricting use of administrative tools like PsExec and PAExec. Implementing strong credential management and network segmentation can help limit lateral movement. Since the ransomware is custom and active, incident response plans should be prepared for containment and recovery.
Affected Countries
Russia
Indicators of Compromise
- hash: 18f61c6d686cffd131c9fd3f3437064b
- hash: 25480dad40152ef3d0c6d38eecc9bd9b
- hash: 34a7f28e0bb69b0d49bacc88bdf20ac1
- hash: 34b8828635f88078735799a3c1ac8e28
- hash: 3a4479b51890373bfc4a011ef41fe376
- hash: 58c0dda52b8f069660166d61fd74f911
- hash: 5d62c1349b8981c396c9a23f4f8f053c
- hash: 780c8f4c6f077da4da96582987920362
- hash: 7dad78584795aa5c160520cc6accf260
- hash: 824ca1e906cc073ee5b0f3519df69a8f
- hash: 9201e35e2993612612919a3c71302cab
- hash: 9969a8221312dba70dd5cbddf83a146c
- hash: 9cd514ff2809ce0b993e3b8649e82a94
- hash: a50eaaf514f4f84e61ca2455a8789753
- hash: a8842616c9057d5cf6e1fe1fa8c3c160
- hash: b893eafed0659f70d4ac250f09073723
- hash: c68b6862725777651085650db34947fc
- hash: d3e06eb34d8eee7ef92cac3ad0a20ff5
- hash: d661cf666b9acbab7cfeae1127a261a9
- hash: d87d0b01d95acc936b7dc47b8f41937a
- hash: de3cfbb50f66079bfee20a6f64e59433
- hash: f08f476f26b01d142ca73923de65fc0c
- hash: f7b9e36e94163a9a303160945f99267a
- hash: fd46a80c2f45577263328984edf7f4dc
- ip: 89.125.66.101
Toy Ghouls’ new toy: the GenieLocker ransomware
Description
GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
GenieLocker is a custom ransomware family operated by the Toy Ghouls group, active since March 2026 and targeting organizations mainly in Russia's manufacturing sector. Unlike their prior use of third-party ransomware like RedAlert, LockBit, and Babuk, GenieLocker is a bespoke malware with two variants: PE for Windows and ELF for Linux/ESXi. The Windows variant includes advanced features such as process termination, service shutdown, anti-debugging, and encryption using libsodium's XChaCha20-Poly1305 algorithm. The attack chain typically begins with compromised VPN credentials from trusted partners, enabling initial access. The group then uses tools like Mimikatz for credential harvesting, SoftPerfect Network Scanner, and SSH utilities for lateral movement, deploying ransomware with PsExec and PAExec.
Potential Impact
Successful exploitation results in encryption of critical systems in targeted organizations, disrupting operations primarily in manufacturing within the Russian Federation. The ransomware's advanced encryption and evasion techniques complicate detection and remediation. The use of compromised VPN credentials and credential theft tools increases the risk of widespread network compromise and lateral movement before ransomware deployment.
Defensive Guidance
No official patch or fix is available as this is malware rather than a software vulnerability. Organizations should focus on securing VPN credentials, monitoring for unauthorized access, and restricting use of administrative tools like PsExec and PAExec. Implementing strong credential management and network segmentation can help limit lateral movement. Since the ransomware is custom and active, incident response plans should be prepared for containment and recovery.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843"]
- Adversary
- Toy Ghouls
- Pulse Id
- 6a6b1c3ea08dbc663eb8f4c0
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash18f61c6d686cffd131c9fd3f3437064b | — | |
hash25480dad40152ef3d0c6d38eecc9bd9b | — | |
hash34a7f28e0bb69b0d49bacc88bdf20ac1 | — | |
hash34b8828635f88078735799a3c1ac8e28 | — | |
hash3a4479b51890373bfc4a011ef41fe376 | — | |
hash58c0dda52b8f069660166d61fd74f911 | — | |
hash5d62c1349b8981c396c9a23f4f8f053c | — | |
hash780c8f4c6f077da4da96582987920362 | — | |
hash7dad78584795aa5c160520cc6accf260 | — | |
hash824ca1e906cc073ee5b0f3519df69a8f | — | |
hash9201e35e2993612612919a3c71302cab | — | |
hash9969a8221312dba70dd5cbddf83a146c | — | |
hash9cd514ff2809ce0b993e3b8649e82a94 | — | |
hasha50eaaf514f4f84e61ca2455a8789753 | — | |
hasha8842616c9057d5cf6e1fe1fa8c3c160 | — | |
hashb893eafed0659f70d4ac250f09073723 | — | |
hashc68b6862725777651085650db34947fc | — | |
hashd3e06eb34d8eee7ef92cac3ad0a20ff5 | — | |
hashd661cf666b9acbab7cfeae1127a261a9 | — | |
hashd87d0b01d95acc936b7dc47b8f41937a | — | |
hashde3cfbb50f66079bfee20a6f64e59433 | — | |
hashf08f476f26b01d142ca73923de65fc0c | — | |
hashf7b9e36e94163a9a303160945f99267a | — | |
hashfd46a80c2f45577263328984edf7f4dc | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip89.125.66.101 | — |
Threat ID: 6a6c3f149c2644c7f869d170
Added to database: 07/31/2026, 06:22:12 UTC
Last enriched: 07/31/2026, 12:43:08 UTC
Last updated: 09/14/2026, 00:22:27 UTC
Views: 193
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.