Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware
ID: 8d513ddc-f2ce-50b4-bd97-4d7b1ccdcbdd
STIX ID: report--8d513ddc-f2ce-50b4-bd97-4d7b1ccdcbdd
Feed Name: The Hacker News
Threat Score
**Bearlyfy**, a pro‑Ukrainian threat actor, has been attributed with 70+ attacks on Russian companies since January 2025 and has recently been deploying a proprietary Windows ransomware called GenieLocker; attacks use exploitation of external services, MeshAgent for remote access, and favor rapid, high‑pressure extortion tactics with ransom demands reaching into the hundreds of thousands of dollars and an estimated ~20% victim payment rate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
