securityonline.info 8/5/2026, 3:50:33 AM · external

GenieLocker ransomware hits Russian firms, linked to Toy Ghouls.

GenieLocker ransomware hits Russian firms, linked to Toy Ghouls.
CyberSIXT Evidence Panel
Primary Source securelist.com
Threat Actor
Toy Ghouls

THE article discusses the emergence of the GenieLocker ransomware, linked to the threat actor group Toy Ghouls, which primarily targets organizations in the Russian Federation—specifically in the manufacturing sector. The ransomware operates on Windows, Linux, and VMware ESXi platforms and utilizes stolen VPN credentials for infiltration. It employs sophisticated encryption without embedding a ransom note, making recovery challenging for victims.

Key capabilities include cross-platform encryption and methods to avoid detection during execution. Kaspersky's analysis indicates that this shift to a custom-built malware signifies a significant enhancement of Toy Ghouls' ransomware toolkit.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline