GenieLocker is a custom cross-platform ransomware family attributed to the financially motivated Toy Ghouls threat group, also known as Bearlyfy, Labubu, and Laboo.boo. Active since March 2026, it has been used primarily against organizations in the Russian Federation, with observed victim sectors including manufacturing, construction, financial services, retail, and technology. The malware represents Toy Ghouls’ shift from using third-party ransomware such as LockBit, Babuk, and RedAlert to an internally developed encryptor.
GenieLocker has distinct Windows and Linux/ESXi variants, enabling operators to impact endpoints, servers, and virtualized infrastructure during the same intrusion. The Windows variant is a PE binary written in C and compiled with MSVC/C++, using libsodium for cryptographic operations. It includes anti-debugging and anti-sandbox measures, including debugger checks, integrity verification of its code section, and a required secret launch argument that must satisfy a hardcoded validation check before encryption begins. It also contains exclusion logic to avoid selected system paths, files, extensions, and hostnames, and it terminates processes and stops services associated with databases, backups, security products, office applications, and virtualization in order to maximize file access and operational disruption.
The Linux/ESXi variant is an ELF binary that is simpler than the Windows build and lacks the Windows-specific secret argument, anti-debugging logic, and exclusion lists. It includes ESXi-focused functionality such as daemonization, stopping active virtual machines, modifying the VMware welcome page, and targeting virtual machine storage by default, allowing encryption of virtual disks and disruption of consolidated virtual environments.
GenieLocker encrypts file contents with XChaCha20-Poly1305 and protects per-file keys with Curve25519-XSalsa20-Poly1305 using an embedded public key. On Windows, it supports chunk-based and partial encryption modes and can traverse local drives and network shares. Observed intrusions associated with GenieLocker involved initial access through stolen valid credentials and abuse of a trusted partner VPN connection, followed by credential theft, network discovery, lateral movement over RDP and SSH, and broad deployment using remote administration utilities. Investigators reported no observed data exfiltration, no public leak site, and no confirmed double-extortion component, indicating operations centered on encryption and business disruption rather than data-leak coercion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Le groupe Toy Ghouls ... a développé un ransomware maison baptisé GenieLocker, actif depuis mars 2026.
The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector... We discovered multiple samples of this Trojan in two variants: PE builds for Windows and ELF builds for Linux and ESXi.
The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector... We discovered multiple samples of this Trojan in two variants: PE builds for Windows and ELF builds for Linux and ESXi.
The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector... We discovered multiple samples of this Trojan in two variants: PE builds for Windows and ELF builds for Linux and ESXi.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The Linux andESXi ELF variants are simpler than their Windows counterparts, lacking both the secret argument and anti-debugging features. However, it includes options focused on ESXi, such as daemonization, worker-thread configuration, delayed execution, and a default target path of /vmfs/volumes.
Entrée via une connexion OpenVPN depuis le réseau d’un partenaire externe (exploitation d’une relation de confiance avec des identifiants volés valides)
Entrée via une connexion OpenVPN depuis le réseau d’un partenaire externe
Entrée via une connexion OpenVPN depuis le réseau d’un partenaire externe (exploitation d’une relation de confiance avec des identifiants volés valides)
Entrée via une connexion OpenVPN depuis le réseau d’un partenaire externe (exploitation d’une relation de confiance avec des identifiants volés valides)
Argument « secret » obligatoire (hex, max 4096 octets, haché en SHA-256) pour démarrer — anti-sandbox Anti-debugging : IsDebuggerPresent , CheckRemoteDebuggerPresent , thread watchdog toutes les 500ms, vérification CRC32 de la section .text
Once inside the network, the attackers deployed OpenSSH, socks5.exe, SoftPerfect Network Scanner, and Mimikatz. SoftPerfect was used to map systems
If the host name is not excluded, GenieLocker starts to kill processes that could be using the files of interest
Finally, GenieLocker starts encryption threads and searches for all available drives, including network shares, to encrypt them.
Argument « secret » obligatoire (hex, max 4096 octets, haché en SHA-256) pour démarrer — anti-sandbox Anti-debugging : IsDebuggerPresent , CheckRemoteDebuggerPresent , thread watchdog toutes les 500ms, vérification CRC32 de la section .text
The widespread deployment of the encryption Trojan was conducted with the legitimate utilities PsExec and PAExec.
They utilized PsExec and PAExec to distribute the ransomware across compromised systems.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom ransomware used by Toy Ghouls since March 2026 to encrypt Windows files and ESXi/Linux VM disks. The Windows variant includes anti-debugging, exclusion lists, process/service termination, and uses XChaCha20-Poly1305 plus Curve25519-XSalsa20-Poly1305; the Linux/ESXi variant is simpler, stops active VMs, modifies /etc/vmware/welcome, and targets /vmfs/volumes.
Ransomware developed in-house by Toy Ghouls that encrypts Windows and Linux/ESXi systems. The Windows variant includes anti-debugging and anti-sandbox checks, process/service termination, and uses XChaCha20-Poly1305 with Curve25519-XSalsa20-Poly1305 for key protection; the Linux/ESXi variant is simpler and targets /vmfs/volumes and modifies /etc/vmware/welcome.
Cross-platform ransomware that targets Windows, Linux, and VMware ESXi systems to encrypt endpoints, servers, and virtual machines in one operation. It uses platform-specific capabilities to maximize disruption and includes techniques to evade analysis and detection.
Cross-platform ransomware targeting Windows, Linux, and VMware ESXi. The Windows variant is a PE-based program written primarily in C with anti-debugging checks and a required secret argument validated via SHA-256 before encryption. It uses libsodium with XChaCha20-Poly1305 for file encryption and Curve25519-XSalsa20-Poly1305 to protect per-file keys. The Linux/ESXi ELF variants are simpler but can stop virtual machines and encrypt virtual disks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.