Toy Ghouls’ new toy: the GenieLocker ransomware
ID: 1e46af07-bb6c-5e00-beaf-b80862c36f4f
STIX ID: report--1e46af07-bb6c-5e00-beaf-b80862c36f4f
Feed Name: Securelist by Kaspersky
This report documents GenieLocker, a newly observed cross-platform ransomware family used by the Toy Ghouls extortion group since March 2026; it analyzes Windows, Linux and ESXi builds, deployment TTPs (credential-based OpenVPN access, discovery and credential theft with Mimikatz and KeePassXC access, lateral movement via RDP/SSH, deployment via PsExec/PAExec and reverse SSH), encryption internals (per-file XChaCha20-Poly1305 with Curve25519 key wrapping), anti-debugging and exclusion lists, observed impact on Russian manufacturing and other sectors, and provides indicators of compromise including hashes, filenames and a C2 IP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
