Toy Ghouls is a financially motivated ransomware and extortion threat actor also tracked as Bearlyfy, Labubu, and Laboo.boo. The group has been active since at least March 2026 and is associated with the in-house GenieLocker ransomware family, marking a shift from prior use of third-party ransomware including LockBit, Babuk, and RedAlert. Toy Ghouls has primarily targeted organizations in the Russian Federation, with observed victimology concentrated in manufacturing and additional activity affecting construction, financial services, retail, and technology organizations. The actor has conducted intrusions by abusing trusted partner relationships and using stolen valid credentials to access victim environments through remote connectivity infrastructure. Post-compromise activity attributed to Toy Ghouls includes deployment of remote administration and tunneling utilities, network scanning, credential dumping, password-store access, lateral movement over RDP and SSH, and broad ransomware deployment using remote execution tools. Observed tradecraft includes credential theft from password managers such as KeePassXC, reconnaissance of internal networks, reverse SSH tunneling for command and control, and mass deployment across Windows and Linux estates. GenieLocker is a cross-platform encryptor with Windows and Linux/VMware ESXi variants. The Windows variant incorporates anti-debugging and anti-sandbox checks, exclusion logic, and process and service termination to maximize encryption impact. The Linux/ESXi variant is simpler but includes virtualization-focused behavior such as stopping active virtual machines and encrypting virtual disks. Across platforms, GenieLocker is designed to disrupt enterprise operations by encrypting endpoints, servers, and virtualized infrastructure. Observed reporting indicates Toy Ghouls has focused on encryption-based ransomware operations rather than data-theft-led extortion. No leak site, data exfiltration, or double-extortion behavior has been observed in connection with GenieLocker at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated cybercriminal group behind the custom GenieLocker ransomware, active since March 2026, targeting primarily organizations in Russia across industrial manufacturing, construction, financial services, retail, and technology sectors.
Financially motivated ransomware group active since March 2026 targeting organizations in Russia. Previously relied on third-party ransomware including RedAlert, LockBit, and Babuk, and now uses its own in-house encryptor, GenieLocker, against Windows and Linux/ESXi environments.
Associated with the use of the GenieLocker cross-platform ransomware family targeting Windows, Linux, and VMware ESXi environments in attacks against Russia.
Financially motivated ransomware operations using the newly identified GenieLocker family against Windows, Linux, and VMware ESXi systems, primarily targeting Russia’s manufacturing sector. The group previously relied on LockBit, Babuk, and RedAlert before shifting to GenieLocker for greater operational control.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.