GenieLocker Ransomware Attacks Target Cross-Platform Systems

GenieLocker ransomware attacks and encryption process overview

Cybercriminals now possess a proprietary tool to simultaneously strike workstations, Linux servers, and corporate virtual infrastructures. Hackers already deploy the new GenieLocker ransomware against Russian organizations. Furthermore, industrial enterprises frequently fall victim to these devastating strikes. This malicious software can halt virtual machines effectively. Subsequently, it encrypts their drives and locks files across accessible network shares.

Toy Ghouls Group Deploys Custom Malware

Kaspersky experts link GenieLocker to the financially motivated Toy Ghouls group. Security researchers also track this collective under the names Bearlyfy, Labubu, and Laboo.boo. Previously, these criminals utilized third-party ransomware like RedAlert, LockBit, and Babuk. However, they now wield their own custom development for Windows, Linux, and VMware ESXi hypervisors. Consequently, this shift drastically reduces their reliance on external malware developers. It also enables a unified encryption mechanism across diverse platforms. Comprehensive insights into this evolution are detailed in recent GenieLocker ransomware for Windows, Linux, and ESXi reports.

Exploiting Trusted Connections for Network Access

Researchers have actively tracked GenieLocker operations since March 2026. During one notable breach in late March, attackers infiltrated a corporate network via an external partner’s OpenVPN connection. Experts suspect the group exploited existing trust relationships between companies. Moreover, they utilized stolen credentials that remained active.

Establishing Footholds and Harvesting Credentials

Following the initial breach, the intruders installed OpenSSH and a proxy server. They also deployed the SoftPerfect Network Scanner alongside the Mimikatz tool. The scanner helped map the internal infrastructure thoroughly. Meanwhile, the attackers used Mimikatz to extract passwords and critical credentials. Evidence additionally points to attempts to access KeePassXC password manager databases on several compromised machines.

Lateral Movement and Encryption Preparation

To navigate the network, the criminals connected to Windows machines via RDP. Alternatively, they accessed Linux servers using SSH. They executed the massive GenieLocker rollout using legitimate PsExec and PAExec utilities. A reverse SSH tunnel maintained constant communication with the command server. Consequently, this setup allowed them to bypass various network restrictions.

Systematically Disabling Windows Defenses

On Windows systems, the ransomware systematically terminates disruptive processes and services. Targeted applications include Microsoft Office, email clients, databases, and backup systems. It also halts 1C components and virtual machine management services. After thorough preparation, GenieLocker aggressively scans for accessible drives and network folders. Then, it launches multiple encryption threads simultaneously. However, the program intentionally skips critical system directories to keep the operating system functional.

Advanced Evasion and Encryption Tactics

The Windows version only executes after receiving a specific secret argument. This clever defense mechanism prevents researchers from accidentally triggering the ransomware in automated sandboxes. Furthermore, it restricts unauthorized criminals from using the tool. GenieLocker also checks for active debuggers every 500 milliseconds. It immediately terminates operation upon detecting any code interference.

Stealthy Ransom Demands and Cryptography

Unlike many other threats, GenieLocker leaves no ransom note on the infected computer. It contains absolutely no contact information for negotiations. Instead, the criminals must deliver their terms to the victim separately. Developers likely abandoned text notes because mass file creation often alerts security solutions. For data encryption, GenieLocker applies the XChaCha20-Poly1305 algorithm. Additionally, it secures each file’s key using Curve25519-XSalsa20-Poly1305. The ransomware can partially corrupt files by targeting random data blocks. This partial encryption significantly accelerates attacks on massive databases.

Expanding Threats to Linux and VMware ESXi

The Linux and ESXi variants operate much more simply. They lack the secret argument, anti-debugging defenses, and exclusion lists. The primary target for this build likely remains VMware ESXi servers. A standard default path leads directly to the /vmfs/volumes directory containing virtual disks. The malware supports delayed execution and worker thread configuration. Its help menu heavily resembles LockBit. Therefore, researchers consider GenieLocker a direct proprietary replacement for previously used tools.

Disrupting Virtual Infrastructure Operations

During attacks, the criminals aggressively halt active virtual machines. Subsequently, they encrypt the underlying virtual disks. Experts have not detected any data theft prior to the locking phase. Toy Ghouls does not utilize a double extortion scheme. They also lack a dedicated leak site for stolen data. Therefore, they pressure victims entirely through infrastructure paralysis and data loss.

Focusing on Russian Industrial Enterprises

Kaspersky telemetry reveals that the vast majority of GenieLocker detections occur within Russian systems. The industrial sector remains the primary target. Construction firms, financial organizations, and retail companies follow closely behind. The introduction of a proprietary cross-platform ransomware significantly expands Toy Ghouls’ capabilities. Consequently, it drastically elevates the risk of destructive attacks against corporate infrastructures.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply