Toy Ghouls: New GenieLocker Ransomware Attacks Windows, ESXi, and Linux Instances

Toy Ghouls: New GenieLocker Ransomware Attacks Windows, ESXi, and Linux Instances

New GenieLocker Ransomware Targets Russian Manufacturing in 2026

A newly identified ransomware strain, GenieLocker, has been deployed by the Toy Ghouls cybercrime group (also tracked as Bearlyfy, Labubu, and Laboo.boo) since March 2026, primarily targeting Russia’s manufacturing sector. The group, previously reliant on third-party ransomware like LockBit, Babuk, and RedAlert, developed GenieLocker to reduce external dependencies and gain full control over its operations.

Attack Methodology

In a late-March 2026 intrusion, attackers breached a victim’s network via an OpenVPN connection from a trusted partner, using stolen credentials to exploit the established trust relationship. Once inside, they deployed tools including:

  • OpenSSH and socks5.exe for persistence
  • SoftPerfect Network Scanner for network mapping
  • Mimikatz for credential theft
  • KeePassXC password managers to extract stored credentials

The group moved laterally using RDP in Windows environments and SSH for Linux hosts, leveraging PsExec and PAExec to distribute ransomware. A reverse SSH tunnel maintained access to their command-and-control infrastructure.

GenieLocker Ransomware Capabilities

The Windows variant, written in C and compiled with Microsoft Visual C++, includes:

  • Anti-debugging checks (IsDebuggerPresent, CheckRemoteDebuggerPresent)
  • A watchdog thread to detect code tampering
  • A secret argument (hexadecimal value) required for execution, validated via SHA-256
  • Process termination of databases, backups, security tools, and virtual machines before encryption

GenieLocker uses XChaCha20-Poly1305 (via libsodium) for file encryption, with per-file keys protected by Curve25519-XSalsa20-Poly1305. Notably, it can encrypt a percentage of a file while still targeting the first chunk even at 0%.

The Linux and VMware ESXi variants are simpler, lacking anti-debugging features but including ESXi-specific options such as:

  • Daemonization and worker-thread configuration
  • Delayed execution
  • Default target path (/vmfs/volumes) for virtual disk encryption
  • Virtual machine termination before encryption

Unlike many ransomware groups, Toy Ghouls does not employ double extortion or operate a public leak site.

Impact & Targets

GenieLocker poses a significant threat to virtualized infrastructure, particularly ESXi environments, where it can halt VMs and encrypt virtual disks. The group’s shift to custom malware suggests increased operational independence, while its focus on Russia’s manufacturing sector indicates a financially motivated campaign with potential for widespread disruption.

Source: https://cybersecuritynews.com/genielocker-ransomware-attack/

Toyota Motor Russia cybersecurity rating report: https://www.rankiteo.com/company/toyota-motor-russia

"id": "TOY1785421466",
"linkid": "toyota-motor-russia",
"type": "Ransomware",
"date": "3/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Manufacturing',
                        'location': 'Russia',
                        'type': 'Manufacturing'}],
 'attack_vector': 'Stolen credentials via OpenVPN connection from a trusted '
                  'partner',
 'data_breach': {'data_encryption': 'Yes (XChaCha20-Poly1305, '
                                    'Curve25519-XSalsa20-Poly1305)',
                 'data_exfiltration': 'No (Toy Ghouls does not employ double '
                                      'extortion or operate a public leak '
                                      'site)'},
 'date_detected': '2026-03',
 'description': 'A newly identified ransomware strain, GenieLocker, has been '
                'deployed by the Toy Ghouls cybercrime group since March 2026, '
                'primarily targeting Russia’s manufacturing sector. The group '
                'developed GenieLocker to reduce external dependencies and '
                'gain full control over its operations. The attack involved '
                'breaching networks via OpenVPN connections, lateral movement '
                'using RDP/SSH, and deployment of ransomware with advanced '
                'encryption capabilities.',
 'impact': {'operational_impact': 'Halt of virtual machines and encryption of '
                                  'virtual disks in ESXi environments',
            'systems_affected': ['Windows', 'Linux', 'VMware ESXi']},
 'initial_access_broker': {'entry_point': 'OpenVPN connection from a trusted '
                                          'partner'},
 'motivation': 'Financial gain',
 'post_incident_analysis': {'root_causes': 'Exploitation of trusted partner '
                                           'credentials via OpenVPN, lateral '
                                           'movement using RDP/SSH, and '
                                           'deployment of custom ransomware'},
 'ransomware': {'data_encryption': 'Yes (XChaCha20-Poly1305, '
                                   'Curve25519-XSalsa20-Poly1305)',
                'data_exfiltration': 'No',
                'ransomware_strain': 'GenieLocker'},
 'references': [{'source': 'Cyber Incident Report'}],
 'threat_actor': 'Toy Ghouls (also tracked as Bearlyfy, Labubu, Laboo.boo)',
 'title': 'New GenieLocker Ransomware Targets Russian Manufacturing in 2026',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.