Toy Ghouls, also known as Bearlyfy, Labubu, Laboo.boo, and Feral Wolf, is a financially motivated ransomware and extortion group active against Russian organizations since at least January 2025. Its victims include manufacturing, construction, financial services, retail, and technology organizations, with manufacturing particularly prominent. The group has used RedAlert, LockBit, and Babuk ransomware, including publicly available or leaked builders, and subsequently adopted custom malware. Toy Ghouls obtains initial access through compromised contractors, exposed services, valid credentials, and insecure configurations of 1C:Enterprise servers. Its post-compromise activities include network scanning, credential dumping with Mimikatz and LSASS memory dumps, extraction of browser and password-manager credentials, and domain compromise through credential-reuse techniques and exploitation of AD CS misconfigurations. Operators move laterally using RDP, SSH, WinRM, and remote-execution utilities such as PsExec and PAExec. Persistence mechanisms include Windows services, scheduled tasks, and local accounts. The group uses reverse SSH tunnels and proxy tools for remote connectivity and clears event logs and connection histories to hinder investigation. Since March 2026, Toy Ghouls has deployed GenieLocker ransomware against Windows, Linux, and VMware ESXi systems. GenieLocker encrypts files and virtual disks using libsodium-based cryptography. Its Windows variant incorporates execution gating, anti-debugging checks, code-integrity monitoring, and termination of processes and services associated with databases, security products, backups, and virtualization. Observed operations emphasize encryption-based ransom demands; data exfiltration, double extortion, and a public stolen-data leak site have not been observed. In early July 2026, Toy Ghouls began deploying custom Bird Agent Windows backdoors, including mqtt-bird-agent and matrix-bird-agent. These variants use HiveMQ MQTT and Matrix/Element, respectively, for command-and-control communications. Delivered through WinRM using Evil-WinRM and WinRM-fs, they collect host telemetry, execute commands through PowerShell or the Windows command shell, and persist as Windows services. Their configuration protections include machine-bound encryption and registry-based storage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
70 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A financially motivated group targeting Russian organizations. It progressed from leaked Babuk and LockBit builders to custom GenieLocker ransomware and custom Bird Agent backdoors using MQTT and Matrix/Element communications for command and control.
Targets Russian organizations using LockBit and Babuk ransomware and custom mqtt-bird-agent and matrix-bird-agent backdoors. The group uses HiveMQ MQTT and Element/Matrix for C2, delivers malware through WinRM, establishes Windows-service persistence, conducts system reconnaissance, and executes remote commands.
Uses newly discovered backdoors for command-and-control, including variants communicating through a HiveMQ MQTT broker and the Matrix-based Element messenger.
Financially motivated group targeting Russian organizations. It evolved from reliance on public tools and leaked ransomware builders to deploying custom Windows backdoors that use MQTT and Matrix/Element services for command-and-control and persistence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.