THE article discusses the emergence of the GenieLocker ransomware, linked to the threat actor group Toy Ghouls, which primarily targets organizations in the Russian Federation—specifically in the manufacturing sector. The ransomware operates on Windows, Linux, and VMware ESXi platforms and utilizes stolen VPN credentials for infiltration. It employs sophisticated encryption without embedding a ransom note, making recovery challenging for victims.
Key capabilities include cross-platform encryption and methods to avoid detection during execution. Kaspersky's analysis indicates that this shift to a custom-built malware signifies a significant enhancement of Toy Ghouls' ransomware toolkit.