The ransomware group Toy Ghouls has launched a custom encryption tool called GenieLocker, targeting manufacturing and industrial organizations across the Russian Federation since March 2026.
Key Points
- GenieLocker is a bespoke ransomware family capable of infecting Windows, Linux, and ESXi environments.
- Attackers gain initial access via compromised OpenVPN credentials and move laterally using RDP, SSH, and tools like Mimikatz.
- The malware utilizes the XChaCha20-Poly1305 encryption algorithm and does not currently employ a double-extortion model or data-leak website.
- Windows variants include anti-debugging features and "secret argument" validation to prevent analysis in sandboxes.
- The Linux and ESXi versions support daemonization and can modify the VMware "Welcome Message" on compromised servers.