Toy Ghouls’ new toy: the GenieLocker ransomware
AI Summary
The GenieLocker ransomware, attributed to the financially motivated threat actor Toy Ghouls (also known as Bearlyfy, Labubu, Laboo.boo), has been active since March 2026 and targets organizations primarily in the Russian Federation, especially in the manufacturing sector. The ransomware is a custom-built encryption Trojan with variants for Windows, Linux, and ESXi, reducing the group's reliance on third-party ransomware. It uses stolen credentials via an OpenVPN connection for initial access, conducts discovery and credential dumping using tools like Mimikatz, moves laterally via RDP and SSH, and deploys the ransomware using PsExec and PAExec. The malware encrypts files using XChaCha20-Poly1305 and stores encrypted keys protected with Curve25519-XSalsa20-Poly1305, with no evidence of data exfiltration, indicating a single-extortion model.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 32 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | a50eaaf514f4f84e61ca2455a8789753 | Details → |
| Filename | kftd.exe | Details → |
| Filename | genie_encrypt.exe | Details → |
| SHA-256 | f08f476f26b01d142ca73923de65fc0c | Details → |
| SHA-256 | fd46a80c2f45577263328984edf7f4dc | Details → |
| SHA-256 | de3cfbb50f66079bfee20a6f64e59433 | Details → |
| SHA-256 | 780c8f4c6f077da4da96582987920362 | Details → |
| Filename | run.exe | Details → |
| Filename | run2.exe | Details → |
| Filename | genie.exe | Details → |
| SHA-256 | 34a7f28e0bb69b0d49bacc88bdf20ac1 | Details → |
| SHA-256 | 5d62c1349b8981c396c9a23f4f8f053c | Details → |
| SHA-256 | a8842616c9057d5cf6e1fe1fa8c3c160 | Details → |
| SHA-256 | 34b8828635f88078735799a3c1ac8e28 | Details → |
| SHA-256 | d3e06eb34d8eee7ef92cac3ad0a20ff5 | Details → |
| SHA-256 | c68b6862725777651085650db34947fc | Details → |
| Filename | consultant.exe | Details → |
| SHA-256 | 9cd514ff2809ce0b993e3b8649e82a94 | Details → |
| SHA-256 | 824ca1e906cc073ee5b0f3519df69a8f | Details → |
| SHA-256 | 25480dad40152ef3d0c6d38eecc9bd9b | Details → |
| SHA-256 | 7dad78584795aa5c160520cc6accf260 | Details → |
| Filename | tempo.exe | Details → |
| Filename | kernel.exe | Details → |
| SHA-256 | 9969a8221312dba70dd5cbddf83a146c | Details → |
| SHA-256 | f7b9e36e94163a9a303160945f99267a | Details → |
| SHA-256 | b893eafed0659f70d4ac250f09073723 | Details → |
| SHA-256 | d661cf666b9acbab7cfeae1127a261a9 | Details → |
| SHA-256 | 3a4479b51890373bfc4a011ef41fe376 | Details → |
| SHA-256 | 58c0dda52b8f069660166d61fd74f911 | Details → |
| SHA-256 | 9201e35e2993612612919a3c71302cab | Details → |
| Filename | vzdump | Details → |
| IP | 89[.]125[.]66[.]101 | Details → |