Also known as: Labubu, APT28, Lockbit Black is here, with a new icon, new ransom note, new wallpaper, tracked as, Laboo.boo, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Lone Wolf, Moonshine Trickster, Ratopak Spider, UAC-0008, Romania, Fancy Bear, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, including diplomatic, maritime, financial, telecom entities, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, Bloody Wolf, SkyCloak, Clubfoot Wolf, Void Arachne, Watch Wolf, Forest Blizzard, TA450, MuddyWater, CHAR, Olalampo, Storm-0842, Red Sandstorm, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code
Bearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a custom Windows ransomware strain known as GenieLocker. The group operates with dual objectives of extortion and sabotage, utilizing a modified version of PolyVice and leveraging vulnerabilities in external services and applications for initial access. Analysis reveals overlaps with PhantomCore, indicating a pro-Ukrainian interest, while Bearlyfy's attacks are characterized by minimal preparation and a focus on immediate impact through data encryption and destruction. Approximately 20% of victims reportedly pay the ransom, with demands escalating to hundreds of thousands of dollars.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Bearlyfy, also known as Labubu, is a cyber threat actor that emerged in January 2025 and has been linked to over 70 attacks targeting Russian companies. The group employs a custom ransomware strain called GenieLocker, focusing on extortion and sabotage through data encryption and destruction. Bearlyfy's activities overlap with PhantomCore, indicating potential pro-Ukrainian motives. Victims report that approximately 20% pay the demanded ransoms, which can exceed hundreds of thousands of dollars.
Goals & Targeting
Bearlyfy targets predominantly Russian companies across various sectors, with a clear emphasis on those that could be associated with sensitive geopolitical interests. The group's dual objectives of extortion and sabotage suggest it seeks both financial gain and disruption to achieve its goals. The targeting of Russian entities aligns with potential pro-Ukrainian motivations, as Bearlyfy appears to share operational patterns with PhantomCore. This indicates a strategic focus on sectors and countries where the impact of such attacks could amplify political or economic pressure.
Enhanced Description
Bearlyfy is a newly emerged cyber threat actor that has gained attention due to its rapid rise and unique operational tactics. Since January 2025, Bearlyfy has targeted Russian companies using a custom ransomware strain named GenieLocker. The group's primary mission appears to be a combination of financial extortion and sabotage, as it encrypts victim data while often causing significant disruption to business operations. Analysis indicates that Bearlyfy uses modified versions of existing tools, such as PolyVice, and exploits vulnerabilities in external services and applications for initial access. This approach suggests moderate technical sophistication but with a focus on quick, impactful campaigns rather than extensive campaign preparation. The group's attacks are characterized by their immediate impact and high demands for ransoms, which often escalate into the hundreds of thousands of dollars. Approximately 20% of Bearlyfy's victims have reportedly paid the ransom, indicating some degree of success in its extortion efforts. Bearlyfy's operations overlap with those of PhantomCore, a known pro-Ukrainian threat group, suggesting potential ideological or operational ties. This alignment also points to Bearlyfy's focus on targeting Russian entities, possibly as part of broader geopolitical cyber conflict dynamics.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Bearlyfy's campaigns are characterized by their rapid execution and high-impact tactics. The group appears to focus on Russian companies, likely due to its potential alignment with pro-Ukrainian objectives. Campaigns often involve minimal preparatory tradecraft but deliver significant disruption through data encryption and destruction. The use of modified PolyVice and vulnerabilities in external services suggests an operational adaptability that allows Bearlyfy to target a wide range of victims effectively. Notable past operations include multiple attacks on Russian businesses, with some resulting in substantial financial losses due to ransom payments.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Bearlyfy's profile is emerging, with limited data available as of April 2025. While its operational methods are partially understood, details on long-term strategic planning and specific technical capabilities remain unclear. The overlap with PhantomCore suggests potential collaboration, but the extent of this relationship is uncertain. Further analysis of Bearlyfy's toolset and attack patterns is needed to fully understand the group's capabilities and motivations.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
44
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics