<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Toy-Ghouls - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/toy-ghouls/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 30 Jul 2026 08:12:07 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/toy-ghouls/feed.xml" rel="self" type="application/rss+xml"/><item><title>Toy Ghouls Deploying Custom GenieLocker Ransomware</title><link>https://feed.craftedsignal.io/briefs/2026-07-genielocker-ransomware/</link><pubDate>Thu, 30 Jul 2026 08:12:07 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-genielocker-ransomware/</guid><description>The Toy Ghouls threat actor is deploying a custom ransomware family called GenieLocker against manufacturing organizations, utilizing compromised VPN credentials and legitimate system tools for lateral movement and encryption.</description><content:encoded><![CDATA[<p>The Toy Ghouls threat group, also known as Bearlyfy or Labubu, has been observed since March 2026 utilizing a new custom ransomware family identified as GenieLocker. This group primarily targets the manufacturing sector, particularly in the Russian Federation. Previously reliant on established third-party ransomware strains such as LockBit and Babuk, Toy Ghouls has transitioned to their own tooling to reduce external dependencies. GenieLocker is distributed in both PE (Windows) and ELF (Linux/ESXi) variants. The ransomware features anti-debugging, environment-specific secret key requirements for execution, and relies on the libsodium library for encryption. Notably, the group does not utilize a data-leak site or double-extortion tactics, relying instead on manual delivery of ransom demands during the impact phase.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial Access: Attackers gain entry via an OpenVPN connection to an external partner's network using compromised but valid credentials.</li>
<li>Discovery: Attackers deploy SoftPerfect Network Scanner to identify internal network resources and assets.</li>
<li>Credential Access: Attackers utilize Mimikatz to dump credentials from memory and access KeePassXC password manager databases on compromised hosts.</li>
<li>Lateral Movement: Attackers move laterally across the environment using RDP for Windows targets and SSH for Linux servers.</li>
<li>Command and Control: Attackers establish a reverse SSH tunnel to facilitate communication with their infrastructure.</li>
<li>Payload Deployment: Attackers use legitimate utilities, specifically PsExec and PAExec, to distribute the GenieLocker ransomware binaries across the target environment.</li>
<li>Impact: On Windows systems, GenieLocker encrypts files; on Linux/ESXi servers, it terminates active virtual machines and encrypts the underlying disk images to complete the impact phase.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Attacks attributed to Toy Ghouls using GenieLocker have primarily affected the manufacturing sector. The ransomware causes significant operational disruption by encrypting file systems and virtual machine disk images. Forensic analysis confirms that the actors do not exfiltrate data, focusing exclusively on operational sabotage and extortion.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the provided Sigma rules to monitor for the execution of unauthorized ransomware binaries and anomalous use of credential harvesting tools like Mimikatz.</li>
<li>Restrict and monitor the use of PsExec and PAExec within the environment; implement strict allowlisting for these binaries to prevent unauthorized remote execution.</li>
<li>Enforce multi-factor authentication (MFA) for all VPN and remote access entry points, specifically targeting the external partner networks identified in the intrusion.</li>
<li>Monitor for the presence of the known GenieLocker hash (5d62c1349b8981c396c9a23f4f8f053c) using Endpoint Detection and Response (EDR) telemetry.</li>
<li>Audit and restrict access to KeePassXC databases and sensitive credential stores on high-value systems.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>ransomware</category><category>extortion</category><category>manufacturing</category><category>toy-ghouls</category></item></channel></rss>