securelist.com 7/30/2026, 8:20:48 AM · external

Toy Ghouls' GenieLocker ransomware hits Russian firms via VPN

Toy Ghouls' GenieLocker ransomware hits Russian firms via VPN
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
Toy Ghouls

THE article discusses the GenieLocker ransomware, attributed to the Toy Ghouls group, which has been active since March 2026. GenieLocker targets Windows, Linux, and ESXi systems, marking a shift for Toy Ghouls away from third-party ransomware. The ransomware is notable for its complex attack vector, starting with an initial access through stolen credentials via OpenVPN.

It employs various tactics for network discovery and credential access, utilizes RDP and SSH for lateral movement, and impacts systems by encrypting files. The Windows version incorporates advanced anti-debugging techniques and a unique encryption routine using the libsodium library, whereas the Linux and ESXi versions are simpler and lack many features. Victims primarily include organizations in the Russian manufacturing sector, with the ransomware not using a double-extortion model.

View full article

Article by CyberSIXT