Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors genesis

Description

Genesis is an emerging ransomware group first observed in late 2025, targeting small to mid-sized US organizations across healthcare, retail, financial services, legal, and manufacturing using double-extortion tactics, focusing heavily on data exfiltration and public leaking. Known victims: 64

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Genesis is an emerging ransomware group targeting small to mid-sized organizations in the US across multiple sectors, utilizing double-extortion tactics with a focus on data exfiltration and public exposure of victim data. The group's operations have evolved since first being observed in late 2025, demonstrating medium sophistication and a clear focus on financial gain through ransom demands and data sales.

Goals & Targeting

Genesis targeting profiles are centered around maximizing financial gain through ransom payments and data exploitation. Their choice of sectors reflects an understanding of which industries have both sensitive data and limited resources to combat attacks effectively. The group's geographic focus appears concentrated on US-based entities, likely due to the higher value placed on data within Western markets and easier access via English language phishing campaigns.

Enhanced Description

Genesis is an active ransomware operation that emerged in late 2025, primarily targeting small to mid-sized businesses across various sectors in the United States. The group employs double-extortion tactics, where victims are forced to pay a ransom to avoid having their stolen data publicly exposed or sold on darknet markets. Genesis has demonstrated a preference for industries with sensitive or valuable data, including healthcare, retail, financial services, legal, and manufacturing. Their attack campaigns often involve sophisticated social engineering techniques and malware deployment, followed by rapid encryption of systems and data extraction. Notable victims include K2 Electric, Catalyst Learning Company, and Secure Health, among others. The group's operational reach and targeting strategy suggest a focus on maximizing impact while remaining under the radar of traditional threat intelligence frameworks.

Key Capabilities

  • Ransomware deployment
  • Double-extortion tactics
  • Spear-phishing campaigns
  • Data exfiltration
  • C2 infrastructure management
  • Malware development
  • Network infiltration

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1078
T1505.001
T1204
T1021

Software / Tooling

Cobalt Strike
Custom Ransomware
AES Encryption Tools
Zipping Utility
Custom Backdoor Malware
Mimikatz-like credential dumping tools

Campaigns & Victims

Genesis campaigns exhibit a high level of operational efficiency, leveraging phishing/malspam as the primary infection vector. The group systematically accesses networks, exfiltrates data, and deploys ransomware to encrypt systems. victims have faced significant disruptions, with healthcare providers and financial services particularly hard-hit. Notable operations include attacks against HMI Elements, CarePoint Health, and OneSource Medical Group.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • C2 communications over HTTP/HTTPS or DNS tunnels
  • Network file access patterns indicating lateral movement
  • Encrypted files following specific naming conventions
  • credential dumping via WMI/Powershell

Recommended Actions

  • Implement MFA for critical systems
  • Enforce network segmentation to limit lateral movement
  • Conduct regular phishing training exercises
  • Deploy robust endpoint detection solutions
  • Monitor for异常数据传输和访问 patterns indicative of exfiltration attempts
  • Develop incident response plans with a focus on ransomware scenarios
  • Regularly back up data and store it offline securely
  • Use network traffic analytics to detect potential C2 activity

Suggested Tags

Ransomware
Double extortion
Data leakage
Financial gain
Healthcare sector
Manufacturing sector
US-targeted

Confidence Assessment

Moderate confidence inGenesis' group details due to emerging nature and limited public disclosures beyond victimology and TTPs. Additional gaps include lack of detailed tooling or infrastructure visibility, and specific attack patterns beyond standard ransomware techniques.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

67

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Critical Infrastructure
Data Exfiltration
Double extortion
Data leakage
Financial gain
Healthcare sector
Manufacturing sector
US-targeted

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 7, 2024
Last Seen
Aug 10, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.