Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors toy ghouls

Also known as: Bearlyfy, Labubu, Laboo.boo, Babuk, APT28, tracked as, bearlyfy, LockBit, the Gourmet, is an enigmatic, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Lone Wolf, Moonshine Trickster, Ratopak Spider, UAC-0008, Romania, Fancy Bear, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, including diplomatic, maritime, financial, telecom entities, Archer RAT, Bloody Wolf, SkyCloak, Clubfoot Wolf, Void Arachne, Watch Wolf, Forest Blizzard, TA450, RUSTRIC, detects installed security software, establishes contact with a, MuddyWater, CHAR, Olalampo, Storm-0842, Red Sandstorm, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris

Description

GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.

Goals & Targeting

Targeted Sectors

Manufacturing
Construction
Financial services
Retail
Government
Energy
Defense
Transportation
Education
Telecommunications
Critical infrastructure
Healthcare
Maritime
Aerospace
Utilities
Aviation
Media
Mining
Non profit
Information technology
Chemical
Nuclear
Gaming
Think tank

Targeted Countries / Regions

Russian Federation
RU
US
PL
AE
IL
IN
KZ
UA
BR
CN
TR
RO
PK
GB
BY
NG
SA
MX
ES
IT
DE
NL
KP

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. attack.mitre.org — Cited by web research for: T1134
  3. www.kaspersky.com — Cited by web research for: Global
  4. learn.microsoft.com — Cited by web research for: Tsunami
  5. gurucul.com — Cited by web research for: Chaos
  6. www.govcert.gv.at — Cited by web research for: CVE-2026-59686

Intel Summary

40

Techniques

48

Tools

0

Campaigns

40

IOCs

0

Observed Data

14

Tactics

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
55%
Added
Aug 1, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.