Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Bearlyfy

Also known as: Labubu, APT28, Lockbit Black is here, with a new icon, new ransom note, new wallpaper, tracked as, Laboo.boo, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Lone Wolf, Moonshine Trickster, Ratopak Spider, UAC-0008, Romania, Fancy Bear, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, including diplomatic, maritime, financial, telecom entities, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, Bloody Wolf, SkyCloak, Clubfoot Wolf, Void Arachne, Watch Wolf, Forest Blizzard, TA450, MuddyWater, CHAR, Olalampo, Storm-0842, Red Sandstorm, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code

Description

Bearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a custom Windows ransomware strain known as GenieLocker. The group operates with dual objectives of extortion and sabotage, utilizing a modified version of PolyVice and leveraging vulnerabilities in external services and applications for initial access. Analysis reveals overlaps with PhantomCore, indicating a pro-Ukrainian interest, while Bearlyfy's attacks are characterized by minimal preparation and a focus on immediate impact through data encryption and destruction. Approximately 20% of victims reportedly pay the ransom, with demands escalating to hundreds of thousands of dollars.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Energy
Manufacturing
Transportation
Media
Education
Critical infrastructure
Construction
Telecommunications
Healthcare
Maritime
Aerospace
Retail
Aviation
Utilities
Chemical
Nuclear
Mining
Information technology
Non profit

Targeted Countries / Regions

RU
UA
US
PL
AE
KZ
BR
IL
TR
RO
PK
GB
BY
NG
SA
MX
ES
IT
DE
IN
NL

AI Analysis

· 1 week ago

Executive Summary

Bearlyfy, also known as Labubu, is a cyber threat actor that emerged in January 2025 and has been linked to over 70 attacks targeting Russian companies. The group employs a custom ransomware strain called GenieLocker, focusing on extortion and sabotage through data encryption and destruction. Bearlyfy's activities overlap with PhantomCore, indicating potential pro-Ukrainian motives. Victims report that approximately 20% pay the demanded ransoms, which can exceed hundreds of thousands of dollars.

Goals & Targeting

Bearlyfy targets predominantly Russian companies across various sectors, with a clear emphasis on those that could be associated with sensitive geopolitical interests. The group's dual objectives of extortion and sabotage suggest it seeks both financial gain and disruption to achieve its goals. The targeting of Russian entities aligns with potential pro-Ukrainian motivations, as Bearlyfy appears to share operational patterns with PhantomCore. This indicates a strategic focus on sectors and countries where the impact of such attacks could amplify political or economic pressure.

Enhanced Description

Bearlyfy is a newly emerged cyber threat actor that has gained attention due to its rapid rise and unique operational tactics. Since January 2025, Bearlyfy has targeted Russian companies using a custom ransomware strain named GenieLocker. The group's primary mission appears to be a combination of financial extortion and sabotage, as it encrypts victim data while often causing significant disruption to business operations. Analysis indicates that Bearlyfy uses modified versions of existing tools, such as PolyVice, and exploits vulnerabilities in external services and applications for initial access. This approach suggests moderate technical sophistication but with a focus on quick, impactful campaigns rather than extensive campaign preparation. The group's attacks are characterized by their immediate impact and high demands for ransoms, which often escalate into the hundreds of thousands of dollars. Approximately 20% of Bearlyfy's victims have reportedly paid the ransom, indicating some degree of success in its extortion efforts. Bearlyfy's operations overlap with those of PhantomCore, a known pro-Ukrainian threat group, suggesting potential ideological or operational ties. This alignment also points to Bearlyfy's focus on targeting Russian entities, possibly as part of broader geopolitical cyber conflict dynamics.

Key Capabilities

  • Custom ransomware (GenieLocker)
  • Modified PolyVice toolset
  • Exploitation of external service vulnerabilities for initial access
  • Quick-impact operational approach
  • Data encryption and destruction techniques

MITRE ATT&CK Tactics

Cyber Espionage
Disruption
Impact
Financial Gain

ATT&CK Techniques

T1059.003
T1078
T1566.001

Software / Tooling

PolyVice
GenieLocker

Campaigns & Victims

Bearlyfy's campaigns are characterized by their rapid execution and high-impact tactics. The group appears to focus on Russian companies, likely due to its potential alignment with pro-Ukrainian objectives. Campaigns often involve minimal preparatory tradecraft but deliver significant disruption through data encryption and destruction. The use of modified PolyVice and vulnerabilities in external services suggests an operational adaptability that allows Bearlyfy to target a wide range of victims effectively. Notable past operations include multiple attacks on Russian businesses, with some resulting in substantial financial losses due to ransom payments.

IOC Patterns

  • Spear-phishing emails targeting Russian companies
  • Use of modified PolyVice for initial access
  • Data encryption using GenieLocker ransomware
  • Exploitation of external service vulnerabilities

Recommended Actions

  • Implement robust email filtering and detection mechanisms to prevent spear-phishing campaigns.
  • Patch and manage external service vulnerabilities regularly.
  • Enhance incident response plans to address potential data encryption events.
  • Conduct regular backups of critical systems to mitigate ransomware impacts.
  • Educate employees on recognizing phishing attempts and suspicious emails.

Suggested Tags

APT
ransomware
espionage
geopolitical
financial

Confidence Assessment

Bearlyfy's profile is emerging, with limited data available as of April 2025. While its operational methods are partially understood, details on long-term strategic planning and specific technical capabilities remain unclear. The overlap with PhantomCore suggests potential collaboration, but the extent of this relationship is uncertain. Further analysis of Bearlyfy's toolset and attack patterns is needed to fully understand the group's capabilities and motivations.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. attack.mitre.org — Cited by web research for: T1548
  3. attack.mitre.org — Cited by web research for: Process Hollowing
  4. www.rescana.com — Cited by web research for: Non Profit
  5. www.crowdstrike.com — Cited by web research for: Fal.Con

Intel Summary

40

Techniques

44

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
APT
ransomware
espionage
geopolitical
financial

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
U
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.