GenieLocker is a cross-platform ransomware family active since March 2026, with Windows PE and Linux/VMware ESXi ELF variants. It is associated with the financially motivated Toy Ghouls threat group, also tracked as Bearlyfy, Laboo.boo, and Feral Wolf. It has primarily affected Russian organizations, particularly manufacturing companies, with additional victims in construction, financial services, retail, and information technology. Its adoption followed the group's use of third-party ransomware, including LockBit, Babuk, and RedAlert.
GenieLocker is deployed after operators compromise and traverse enterprise networks. Documented intrusions have involved trusted partner VPN access, exploitation of Atlassian Confluence CVE-2023-22515, and abuse of insecure internet-exposed 1C:Enterprise configurations. Operators use separate tools for network discovery, credential theft, remote access, and lateral movement, including RDP and SSH, and have distributed the ransomware at scale using PsExec and PAExec. These intrusion activities are distinct from the encryptor's own functionality.
Both variants use libsodium-based cryptography, encrypting file contents and metadata with XChaCha20-Poly1305 and protecting unique per-file encryption keys with Curve25519-XSalsa20-Poly1305 and an embedded attacker-controlled public key. The malware supports configurable partial encryption. The Windows variant searches accessible drives and network shares, excludes selected system files and directories, and terminates application processes and services associated with databases, backups, security products, and virtualization. Execution requires a secret hexadecimal argument that passes a hardcoded SHA-256 check. Repeated debugger checks and CRC32 verification of executable code provide anti-analysis and tamper detection. The analyzed Windows implementation does not automatically create ransom notes; operators deliver ransom demands separately.
The Linux/ESXi variant lacks the Windows execution-secret requirement, anti-debugging mechanisms, and exclusion lists. It supports configurable worker threads, delayed execution, recursive directory processing, and daemonization, and is oriented toward encrypting ESXi datastore contents and virtual disks. Deployments have included stopping virtual machines before encryption. A documented March 2026 intrusion showed no evidence of data exfiltration or double extortion; the observed operation focused on encryption-based extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One intrusion began with a publicly accessible Confluence server running inside a Docker container behind a proxy. Feral Wolf exploited CVE-2023-22515, created an account, and placed it in the Confluence administrator group.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Новое семейство шифровальщиков GenieLocker, активное с марта 2026 года, было замечено в атаках на российские организации преимущественно из промышленного сектора.
GenieLocker is cited as Bearlyfy’s self-developed ransomware and as a design comparison for VantaCore ransomware.
The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector... We discovered multiple samples of this Trojan in two variants: PE builds for Windows and ELF builds for Linux and ESXi.
The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector... We discovered multiple samples of this Trojan in two variants: PE builds for Windows and ELF builds for Linux and ESXi.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The Linux andESXi ELF variants are simpler than their Windows counterparts, lacking both the secret argument and anti-debugging features. However, it includes options focused on ESXi, such as daemonization, worker-thread configuration, delayed execution, and a default target path of /vmfs/volumes.
Entrée via une connexion OpenVPN depuis le réseau d’un partenaire externe (exploitation d’une relation de confiance avec des identifiants volés valides)
Entrée via une connexion OpenVPN depuis le réseau d’un partenaire externe
Entrée via une connexion OpenVPN depuis le réseau d’un partenaire externe (exploitation d’une relation de confiance avec des identifiants volés valides)
Entrée via une connexion OpenVPN depuis le réseau d’un partenaire externe (exploitation d’une relation de confiance avec des identifiants volés valides)
Once inside the network, the attackers deployed OpenSSH, socks5.exe, SoftPerfect Network Scanner, and Mimikatz. SoftPerfect was used to map systems
If the host name is not excluded, GenieLocker starts to kill processes that could be using the files of interest
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used as the final payload to encrypt victim data following Feral Wolf intrusions.
Ransomware deployed by Feral Wolf to encrypt victim data following initial access, lateral movement, and credential theft.
Ransomware deployed by Feral Wolf to encrypt corporate data following initial access, lateral movement, and credential theft.
Custom ransomware developed and used by Toy Ghouls before its transition to a bespoke backdoor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.