logo

Toy Ghouls’ new toy: the GenieLocker ransomware

ID: 1e46af07-bb6c-5e00-beaf-b80862c36f4f

STIX ID: report--1e46af07-bb6c-5e00-beaf-b80862c36f4f

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2026-07-30

Date Updated: 2026-07-30

Author: Fedor Sinitsyn, Yanis Zinchenko

...
...

This report documents GenieLocker, a newly observed cross-platform ransomware family used by the Toy Ghouls extortion group since March 2026; it analyzes Windows, Linux and ESXi builds, deployment TTPs (credential-based OpenVPN access, discovery and credential theft with Mimikatz and KeePassXC access, lateral movement via RDP/SSH, deployment via PsExec/PAExec and reverse SSH), encryption internals (per-file XChaCha20-Poly1305 with Curve25519 key wrapping), anti-debugging and exclusion lists, observed impact on Russian manufacturing and other sectors, and provides indicators of compromise including hashes, filenames and a C2 IP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.