GenieLocker Ransomware Targets Russian Manufacturers on Windows, Linux, and ESXi
ID: 46b1d433-8925-53ac-b600-314b5655ea8b
STIX ID: report--46b1d433-8925-53ac-b600-314b5655ea8b
Feed Name: securityonline.info
Kaspersky documented a new cross-platform ransomware called GenieLocker (Windows PE and ELF for Linux/ESXi) used by the Toy Ghouls group since March 2026; attackers used stolen OpenVPN credentials from a trusted partner to deploy tooling (Mimikatz, OpenSSH, network scanner) and mass-deploy the ransomware via PsExec/PAExec and reverse SSH, encrypting files with libsodium-based XChaCha20-Poly1305 and protecting per-file keys with Curve25519—targeting primarily Russian organizations across manufacturing and other sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
