Genesis is an emerging ransomware group first observed in late 2025, targeting small to mid-sized US organizations across healthcare, retail, financial services, legal, and manufacturing using double-extortion tactics, focusing heavily on data exfiltration and public leaking. Known victims: 64
Objectives
Executive Summary
Genesis is an emerging ransomware group targeting small to mid-sized organizations in the US across multiple sectors, utilizing double-extortion tactics with a focus on data exfiltration and public exposure of victim data. The group's operations have evolved since first being observed in late 2025, demonstrating medium sophistication and a clear focus on financial gain through ransom demands and data sales.
Goals & Targeting
Genesis targeting profiles are centered around maximizing financial gain through ransom payments and data exploitation. Their choice of sectors reflects an understanding of which industries have both sensitive data and limited resources to combat attacks effectively. The group's geographic focus appears concentrated on US-based entities, likely due to the higher value placed on data within Western markets and easier access via English language phishing campaigns.
Enhanced Description
Genesis is an active ransomware operation that emerged in late 2025, primarily targeting small to mid-sized businesses across various sectors in the United States. The group employs double-extortion tactics, where victims are forced to pay a ransom to avoid having their stolen data publicly exposed or sold on darknet markets. Genesis has demonstrated a preference for industries with sensitive or valuable data, including healthcare, retail, financial services, legal, and manufacturing. Their attack campaigns often involve sophisticated social engineering techniques and malware deployment, followed by rapid encryption of systems and data extraction. Notable victims include K2 Electric, Catalyst Learning Company, and Secure Health, among others. The group's operational reach and targeting strategy suggest a focus on maximizing impact while remaining under the radar of traditional threat intelligence frameworks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Genesis campaigns exhibit a high level of operational efficiency, leveraging phishing/malspam as the primary infection vector. The group systematically accesses networks, exfiltrates data, and deploys ransomware to encrypt systems. victims have faced significant disruptions, with healthcare providers and financial services particularly hard-hit. Notable operations include attacks against HMI Elements, CarePoint Health, and OneSource Medical Group.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence inGenesis' group details due to emerging nature and limited public disclosures beyond victimology and TTPs. Additional gaps include lack of detailed tooling or infrastructure visibility, and specific attack patterns beyond standard ransomware techniques.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
67
Campaigns
0
IOCs
0
Observed Data
0
Tactics