OpenVPN: New Cross-Platform Ransomware Encrypts Windows, Linux, and VMware Infrastructure

OpenVPN: New Cross-Platform Ransomware Encrypts Windows, Linux, and VMware Infrastructure

GenieLocker: Toy Ghouls’ Cross-Platform Ransomware Targets Manufacturing and Virtualized Environments

A newly discovered ransomware strain, GenieLocker, has emerged as a sophisticated cross-platform threat, enabling attacks on Windows, Linux, and VMware ESXi systems. Developed by the Toy Ghouls threat group, this malware marks a shift from their previous reliance on commodity ransomware like LockBit and Babuk, signaling a move toward custom-built capabilities.

First detected in March 2026, GenieLocker has primarily targeted manufacturing organizations, though infections have also been observed in the construction and financial sectors, with a concentration in Russia. Unlike many ransomware families, Toy Ghouls appears to focus solely on encryption-based extortion, with no evidence of data exfiltration or double-extortion tactics.

Infection Chain and Tactics

Initial access was achieved through compromised OpenVPN connections linked to trusted third-party partners, leveraging stolen credentials to infiltrate networks. Once inside, attackers deployed a suite of post-exploitation tools, including:

  • OpenSSH, SoftPerfect Network Scanner, and Mimikatz for reconnaissance and credential harvesting.
  • KeePassXC password vaults as a target for credential extraction.
  • RDP (Windows) and SSH (Linux) for lateral movement.
  • PsExec and PAExec for payload deployment, with reverse SSH tunnels maintaining command-and-control communications.

Technical Capabilities

GenieLocker employs advanced cryptographic mechanisms, using the libsodium library with XChaCha20-Poly1305 (AEAD cipher) for file encryption and Curve25519-based public key cryptography to secure per-file keys. Key features include:

  • Partial file encryption, allowing attackers to specify the percentage of data encrypted an optimization for large datasets.
  • Cross-platform disruption:
    • On Windows, it terminates processes and services (e.g., databases, backup agents, VM components) to facilitate encryption.
    • On ESXi servers, it halts running virtual machines before encrypting their disks, crippling virtualized infrastructure.
  • Anti-analysis protections (Windows variant only):
    • A hardcoded "secret argument" required for execution.
    • Anti-debugging checks via Windows API functions.
    • CRC32 hashing for code integrity verification, hindering reverse engineering.
  • Stealth tactics: No ransom notes are dropped; negotiation details are delivered manually during the intrusion to evade behavioral detection.

The Linux and ESXi variants are streamlined but include daemonization and ESXi system message modifications, ensuring consistency in encryption logic across platforms.

Detection and Implications

Security vendors currently detect GenieLocker under signatures such as Trojan-Ransom.Win64.Agent.genie and Trojan-Ransom.Linux.Agent.genie. Its emergence reflects a broader trend of threat actors developing bespoke, cross-platform ransomware to maximize impact while reducing dependence on public malware frameworks. The shift toward custom tooling and third-party access exploitation underscores the evolving sophistication of ransomware operations.

Source: https://cyberpress.org/new-cross-platform-ransomware/

OpenVPN Inc. cybersecurity rating report: https://www.rankiteo.com/company/openvpn

"id": "OPE1785414450",
"linkid": "openvpn",
"type": "Cyber Attack",
"date": "3/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Manufacturing',
                        'location': 'Russia',
                        'type': 'Organization'},
                       {'industry': 'Construction',
                        'location': 'Russia',
                        'type': 'Organization'},
                       {'industry': 'Financial',
                        'location': 'Russia',
                        'type': 'Organization'}],
 'attack_vector': 'Compromised OpenVPN connections via stolen credentials from '
                  'trusted third-party partners',
 'data_breach': {'data_encryption': 'XChaCha20-Poly1305 (AEAD cipher) with '
                                    'Curve25519-based public key cryptography',
                 'data_exfiltration': 'No evidence of data exfiltration'},
 'date_detected': '2026-03',
 'description': 'A newly discovered ransomware strain, GenieLocker, has '
                'emerged as a sophisticated cross-platform threat, enabling '
                'attacks on Windows, Linux, and VMware ESXi systems. Developed '
                'by the Toy Ghouls threat group, this malware marks a shift '
                'from their previous reliance on commodity ransomware like '
                'LockBit and Babuk, signaling a move toward custom-built '
                'capabilities. GenieLocker primarily targets manufacturing '
                'organizations but has also affected construction and '
                'financial sectors, with a concentration in Russia. The '
                'ransomware focuses solely on encryption-based extortion '
                'without evidence of data exfiltration or double-extortion '
                'tactics.',
 'impact': {'operational_impact': 'Termination of critical processes/services '
                                  '(databases, backup agents, VM components), '
                                  'halting of virtual machines on ESXi servers',
            'systems_affected': 'Windows, Linux, VMware ESXi'},
 'initial_access_broker': {'entry_point': 'Compromised OpenVPN connections via '
                                          'stolen credentials from trusted '
                                          'third-party partners'},
 'motivation': 'Encryption-based extortion',
 'post_incident_analysis': {'root_causes': 'Compromised OpenVPN connections '
                                           'via stolen credentials; use of '
                                           'post-exploitation tools (OpenSSH, '
                                           'SoftPerfect Network Scanner, '
                                           'Mimikatz, KeePassXC) for '
                                           'reconnaissance and lateral '
                                           'movement'},
 'ransomware': {'data_encryption': 'XChaCha20-Poly1305 (AEAD cipher) with '
                                   'Curve25519-based public key cryptography; '
                                   'partial file encryption',
                'data_exfiltration': 'No evidence of data exfiltration',
                'ransomware_strain': 'GenieLocker'},
 'references': [{'source': 'Cyber Incident Description'}],
 'threat_actor': 'Toy Ghouls',
 'title': 'GenieLocker: Toy Ghouls’ Cross-Platform Ransomware Targets '
          'Manufacturing and Virtualized Environments',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.