logo

Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware

ID: 8d513ddc-f2ce-50b4-bd97-4d7b1ccdcbdd

STIX ID: report--8d513ddc-f2ce-50b4-bd97-4d7b1ccdcbdd

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-27

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Bearlyfy**, a pro‑Ukrainian threat actor, has been attributed with 70+ attacks on Russian companies since January 2025 and has recently been deploying a proprietary Windows ransomware called GenieLocker; attacks use exploitation of external services, MeshAgent for remote access, and favor rapid, high‑pressure extortion tactics with ransom demands reaching into the hundreds of thousands of dollars and an estimated ~20% victim payment rate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.