Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Toy Ghouls’ new toy: the GenieLocker ransomware

34b8828635f88078735799a3c1ac8e28

TLP:CLEAR
Active

MD5 Hash

Description

GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Toy Ghouls’ new toy: the GenieLocker ransomware
Pattern Type
STIX
Confidence
75%
Valid From
Aug 1, 2026 18:02
Total Sightings
0
Added
Aug 1, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 34b8828635f88078735799a3c1ac8e28

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.