AUTO-UPDATED

Toy Ghouls’ new toy: the GenieLocker ransomware

The ransomware group Toy Ghouls has launched a custom encryption tool called GenieLocker, targeting manufacturing and industrial organizations across the Russian Federation since March 2026.

Key Points

  • GenieLocker is a bespoke ransomware family capable of infecting Windows, Linux, and ESXi environments.
  • Attackers gain initial access via compromised OpenVPN credentials and move laterally using RDP, SSH, and tools like Mimikatz.
  • The malware utilizes the XChaCha20-Poly1305 encryption algorithm and does not currently employ a double-extortion model or data-leak website.
  • Windows variants include anti-debugging features and "secret argument" validation to prevent analysis in sandboxes.
  • The Linux and ESXi versions support daemonization and can modify the VMware "Welcome Message" on compromised servers.

Why it Matters

The shift to custom-built ransomware indicates that the Toy Ghouls group is maturing its operations to reduce reliance on third-party software. This development poses a significant threat to industrial sectors, as the unified, cross-platform nature of GenieLocker allows for more efficient and coordinated attacks on critical infrastructure.
Securelist.com Published by Fedor Sinitsyn, Yanis Zinchenko
Read original