Toy Ghouls’ new toy: the GenieLocker ransomware

Toy Ghouls’ new toy: the GenieLocker ransomware
GenieLocker is a custom ransomware family used by Toy Ghouls against Russian organizations, especially in manufacturing, with Windows, Linux, and ESXi variants active since March 2026. The group used stolen OpenVPN credentials for entry, deployed tools like Mimikatz and PsExec, and encrypted systems without evidence of data theft or double extortion. #GenieLocker #ToyGhouls #Bearlyfy #Labubu #Laboo.boo #Mimikatz #PsExec #OpenVPN

Keypoints

  • GenieLocker is a custom ransomware family attributed to the Toy Ghouls threat group and active since March 2026.
  • The main victims were organizations in the Russian Federation, with manufacturing most affected and construction, financial services, retail, and technology also impacted.
  • Initial access was likely gained through an OpenVPN connection from an external partner network using stolen valid credentials.
  • The attackers used tools such as OpenSSH, socks5.exe, SoftPerfect Network Scanner, Mimikatz, PsExec, and PAExec for discovery, credential theft, lateral movement, and deployment.
  • No evidence of data exfiltration was found, and the group did not use a double-extortion model or data-leak site.
  • GenieLocker has separate Windows and Linux/ESXi builds, uses libsodium, and encrypts files with XChaCha20-Poly1305 and Curve25519-XSalsa20-Poly1305.
  • The malware includes anti-debugging, secret-argument validation, process and service termination, exclusion lists, and ESXi-specific features like daemonizing and welcome-message modification.

MITRE Techniques

  • [T1133] External Remote Services – Initial access was achieved through an OpenVPN connection from an external partner network (‘the attackers first entered the environment through an OpenVPN connection originating from an external partner’s network’).
  • [T1078] Valid Accounts – The attackers likely used stolen but still valid credentials to access the target (‘used stolen, yet still valid, credentials to connect’).
  • [T1046] Network Service Scanning – SoftPerfect Network Scanner was used for discovery (‘They employed SoftPerfect Network Scanner for discovery’).
  • [T1003] OS Credential Dumping – Mimikatz was used to dump credentials (‘used Mimikatz to dump credentials’).
  • [T1110] Brute Force – Not explicitly described as brute force; skip.
  • [T1219] Remote Access Software – OpenSSH and socks5.exe were installed on compromised hosts as additional remote access tooling (‘installed additional tools… including OpenSSH, socks5.exe’).
  • [T1021.001] Remote Services: Remote Desktop Protocol – Lateral movement to Windows machines was done with RDP (‘Lateral movement was performed by using RDP to reach Windows machines’).
  • [T1021.004] Remote Services: SSH – Lateral movement to Linux servers was done with SSH (‘and SSH for Linux servers’).
  • [T1569.002] Service Execution – PsExec and PAExec were used to deploy the ransomware broadly (‘widespread deployment … with the legitimate utilities PsExec and PAExec’).
  • [T1090.001] Proxy: Internal Proxy – The attackers established a reverse SSH tunnel for C2 communication (‘established a reverse SSH tunnel to communicate with their command-and-control server’).
  • [T1486] Data Encrypted for Impact – Files and VM disks were encrypted on Windows, Linux, and ESXi systems (‘encrypted files on the compromised Windows machines’ and ‘encrypted their disks’).
  • [T1529] System Shutdown / Reboot – Active virtual machines were stopped before disk encryption (‘they stopped active virtual machines’).
  • [T1562.001] Impair Defenses: Disable or Modify Tools – The malware terminates processes and stops services that might block encryption (‘starts to kill processes’ and ‘stops the following services’).
  • [T1105] Ingress Tool Transfer – Additional tools such as OpenSSH, socks5.exe, SoftPerfect Network Scanner, and Mimikatz were placed on hosts after intrusion (‘installed additional tools on the compromised hosts’).
  • [T1027] Obfuscated Files or Information – The secret hex argument and hashing checks may be intended to hinder sandboxing and analysis (‘the purpose of this is to avoid execution on sandboxes and other automated analysis environments’).
  • [T1057] Process Discovery – Process names and targeted applications were enumerated for termination (‘kills processes that could be using the files of interest’).
  • [T1497.001] Virtualization/Sandbox Evasion: System Checks – Environment and debugger checks were used to detect analysis environments (‘Environment check’ and ‘detect the debugger’).

Indicators of Compromise

  • [File hash ] Windows GenieLocker sample – MD5 5d62c1349b8981c396c9a23f4f8f053c, MD5 9201e35e2993612612919a3c71302cab
  • [File hash ] Additional samples / variants – A50EAAF514F4F84E61CA2455A8789753, 34A7F28E0BB69B0D49BACC88BDF20AC1
  • [File hash ] Additional samples / variants – A8842616C9057D5CF6E1FE1FA8C3C16034B8828635F88078735799A3C1AC8E28, 9CD514FF2809CE0B993E3B8649E82A94824CA1E906CC073EE5B0F3519DF69A8F25480DAD40152EF3D0C6D38EECC9BD9B7DAD78584795AA5C160520CC6ACCF26018F61C6D686CFFD131C9FD3F3437064B
  • [File names ] Observed sample names and dropped tooling – kftd.exe, genie_encrypt.exe, run.exe, run2.exe, genie.exe, consultant.exe, tempo.exe, kernel.exe, vzdump
  • [Network address ] C2 server – 89.125.66.101
  • [Email address ] Kaspersky TI contact – [email protected]
  • [Encryption extension / artifact ] Encrypted file extension and related artifacts – .03ffc1c4a3da0f02, .03ffc1c4a3da0f02.lock, 03ffc1c4a3da0f02.journal
  • [File path ] ESXi welcome-message path – /etc/vmware/welcome


Read more: https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/