{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/actors/toy-ghouls/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":["Toy Ghouls"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows","Linux","ESXi","OpenVPN","KeePassXC","PsExec","PAExec"],"_cs_severities":["high"],"_cs_tags":["ransomware","extortion","manufacturing","toy-ghouls"],"_cs_type":"threat","_cs_vendors":["Microsoft","VMware"],"content_html":"\u003cp\u003eThe Toy Ghouls threat group, also known as Bearlyfy or Labubu, has been observed since March 2026 utilizing a new custom ransomware family identified as GenieLocker. This group primarily targets the manufacturing sector, particularly in the Russian Federation. Previously reliant on established third-party ransomware strains such as LockBit and Babuk, Toy Ghouls has transitioned to their own tooling to reduce external dependencies. GenieLocker is distributed in both PE (Windows) and ELF (Linux/ESXi) variants. The ransomware features anti-debugging, environment-specific secret key requirements for execution, and relies on the libsodium library for encryption. Notably, the group does not utilize a data-leak site or double-extortion tactics, relying instead on manual delivery of ransom demands during the impact phase.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial Access: Attackers gain entry via an OpenVPN connection to an external partner's network using compromised but valid credentials.\u003c/li\u003e\n\u003cli\u003eDiscovery: Attackers deploy SoftPerfect Network Scanner to identify internal network resources and assets.\u003c/li\u003e\n\u003cli\u003eCredential Access: Attackers utilize Mimikatz to dump credentials from memory and access KeePassXC password manager databases on compromised hosts.\u003c/li\u003e\n\u003cli\u003eLateral Movement: Attackers move laterally across the environment using RDP for Windows targets and SSH for Linux servers.\u003c/li\u003e\n\u003cli\u003eCommand and Control: Attackers establish a reverse SSH tunnel to facilitate communication with their infrastructure.\u003c/li\u003e\n\u003cli\u003ePayload Deployment: Attackers use legitimate utilities, specifically PsExec and PAExec, to distribute the GenieLocker ransomware binaries across the target environment.\u003c/li\u003e\n\u003cli\u003eImpact: On Windows systems, GenieLocker encrypts files; on Linux/ESXi servers, it terminates active virtual machines and encrypts the underlying disk images to complete the impact phase.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eAttacks attributed to Toy Ghouls using GenieLocker have primarily affected the manufacturing sector. The ransomware causes significant operational disruption by encrypting file systems and virtual machine disk images. Forensic analysis confirms that the actors do not exfiltrate data, focusing exclusively on operational sabotage and extortion.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rules to monitor for the execution of unauthorized ransomware binaries and anomalous use of credential harvesting tools like Mimikatz.\u003c/li\u003e\n\u003cli\u003eRestrict and monitor the use of PsExec and PAExec within the environment; implement strict allowlisting for these binaries to prevent unauthorized remote execution.\u003c/li\u003e\n\u003cli\u003eEnforce multi-factor authentication (MFA) for all VPN and remote access entry points, specifically targeting the external partner networks identified in the intrusion.\u003c/li\u003e\n\u003cli\u003eMonitor for the presence of the known GenieLocker hash (5d62c1349b8981c396c9a23f4f8f053c) using Endpoint Detection and Response (EDR) telemetry.\u003c/li\u003e\n\u003cli\u003eAudit and restrict access to KeePassXC databases and sensitive credential stores on high-value systems.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T08:12:07Z","date_published":"2026-07-30T08:12:07Z","id":"https://feed.craftedsignal.io/briefs/2026-07-genielocker-ransomware/","summary":"The Toy Ghouls threat actor is deploying a custom ransomware family called GenieLocker against manufacturing organizations, utilizing compromised VPN credentials and legitimate system tools for lateral movement and encryption.","title":"Toy Ghouls Deploying Custom GenieLocker Ransomware","url":"https://feed.craftedsignal.io/briefs/2026-07-genielocker-ransomware/"}],"language":"en","title":"CraftedSignal Threat Feed - Toy Ghouls","version":"https://jsonfeed.org/version/1.1"}