securelist · Crawled Jul 31, 2026

Toy Ghouls’ new toy: the GenieLocker ransomware

32 IoCs 1 Actors
Read original article ↗

AI Summary

The GenieLocker ransomware, attributed to the financially motivated threat actor Toy Ghouls (also known as Bearlyfy, Labubu, Laboo.boo), has been active since March 2026 and targets organizations primarily in the Russian Federation, especially in the manufacturing sector. The ransomware is a custom-built encryption Trojan with variants for Windows, Linux, and ESXi, reducing the group's reliance on third-party ransomware. It uses stolen credentials via an OpenVPN connection for initial access, conducts discovery and credential dumping using tools like Mimikatz, moves laterally via RDP and SSH, and deploys the ransomware using PsExec and PAExec. The malware encrypts files using XChaCha20-Poly1305 and stores encrypted keys protected with Curve25519-XSalsa20-Poly1305, with no evidence of data exfiltration, indicating a single-extortion model.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 32 extracted

Type Value Detail
SHA-256 a50eaaf514f4f84e61ca2455a8789753 Details →
Filename kftd.exe Details →
Filename genie_encrypt.exe Details →
SHA-256 f08f476f26b01d142ca73923de65fc0c Details →
SHA-256 fd46a80c2f45577263328984edf7f4dc Details →
SHA-256 de3cfbb50f66079bfee20a6f64e59433 Details →
SHA-256 780c8f4c6f077da4da96582987920362 Details →
Filename run.exe Details →
Filename run2.exe Details →
Filename genie.exe Details →
SHA-256 34a7f28e0bb69b0d49bacc88bdf20ac1 Details →
SHA-256 5d62c1349b8981c396c9a23f4f8f053c Details →
SHA-256 a8842616c9057d5cf6e1fe1fa8c3c160 Details →
SHA-256 34b8828635f88078735799a3c1ac8e28 Details →
SHA-256 d3e06eb34d8eee7ef92cac3ad0a20ff5 Details →
SHA-256 c68b6862725777651085650db34947fc Details →
Filename consultant.exe Details →
SHA-256 9cd514ff2809ce0b993e3b8649e82a94 Details →
SHA-256 824ca1e906cc073ee5b0f3519df69a8f Details →
SHA-256 25480dad40152ef3d0c6d38eecc9bd9b Details →
SHA-256 7dad78584795aa5c160520cc6accf260 Details →
Filename tempo.exe Details →
Filename kernel.exe Details →
SHA-256 9969a8221312dba70dd5cbddf83a146c Details →
SHA-256 f7b9e36e94163a9a303160945f99267a Details →
SHA-256 b893eafed0659f70d4ac250f09073723 Details →
SHA-256 d661cf666b9acbab7cfeae1127a261a9 Details →
SHA-256 3a4479b51890373bfc4a011ef41fe376 Details →
SHA-256 58c0dda52b8f069660166d61fd74f911 Details →
SHA-256 9201e35e2993612612919a3c71302cab Details →
Filename vzdump Details →
IP 89[.]125[.]66[.]101 Details →

MITRE ATT&CK TTPs 8 techniques