Threat Actor πΊπ¦ Ukraine
Bearlyfy
Also known as: Labubu
Bearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a custom Windows ransomware strain known as GenieLocker. The group operates with dual objectives of extortion and sabotage, utilizing a modified version of PolyVice and leveraging vulnerabilities in external services and applications for initial access. Analysis reveals overlaps with PhantomCore, indicating a pro-Ukrainian interest, while Bearlyfy's attacks are characterized by minimal preparation and a focus on immediate impact through data encryption and destruction. Approximately 20% of victims reportedly pay the ransom, with demands escalating to hundreds of thousands of dollars.
Indicators of Compromise 32
Filename consultant.exe Filename genie.exe Filename genie_encrypt.exe Filename kernel.exe Filename kftd.exe Filename run.exe Filename run2.exe Filename tempo.exe Filename vzdump SHA-256 25480dad40152ef3d0c6d38eecc9bd9b SHA-256 34a7f28e0bb69b0d49bacc88bdf20ac1 SHA-256 34b8828635f88078735799a3c1ac8e28 SHA-256 3a4479b51890373bfc4a011ef41fe376 SHA-256 58c0dda52b8f069660166d61fd74f911 SHA-256 5d62c1349b8981c396c9a23f4f8f053c SHA-256 780c8f4c6f077da4da96582987920362 SHA-256 7dad78584795aa5c160520cc6accf260 SHA-256 824ca1e906cc073ee5b0f3519df69a8f SHA-256 9201e35e2993612612919a3c71302cab SHA-256 9969a8221312dba70dd5cbddf83a146c SHA-256 9cd514ff2809ce0b993e3b8649e82a94 SHA-256 a50eaaf514f4f84e61ca2455a8789753 SHA-256 a8842616c9057d5cf6e1fe1fa8c3c160 SHA-256 b893eafed0659f70d4ac250f09073723 SHA-256 c68b6862725777651085650db34947fc SHA-256 d3e06eb34d8eee7ef92cac3ad0a20ff5 SHA-256 d661cf666b9acbab7cfeae1127a261a9 SHA-256 de3cfbb50f66079bfee20a6f64e59433 SHA-256 f08f476f26b01d142ca73923de65fc0c SHA-256 f7b9e36e94163a9a303160945f99267a SHA-256 fd46a80c2f45577263328984edf7f4dc IP 89[.]125[.]66[.]101
MITRE ATT&CK TTPs 8
T1003 T1018 T1021 T1048 T1055 T1059 T1078 T1486
OS Credential Dumping
Credential Access
Remote System Discovery
Discovery
Remote Services
Lateral Movement
Exfiltration Over Alternative Protocol
Exfiltration
Process Injection
Defense Evasion
Command and Scripting Interpreter
Execution
Valid Accounts
Defense Evasion
Data Encrypted for Impact
Impact