GenieLocker Ransomware Targets Windows, Linux, and ESXi Systems, Leaves No Ransom Note

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Custom Trojan: Kaspersky's Securelist documented GenieLocker, a new ransomware family active since March 2026 and attributed to the Toy Ghouls group.
  • Cross-Platform Reach: The malware ships as PE builds for Windows and ELF builds for Linux and ESXi, unifying encryption across all three.
  • Initial Access: Attacks leveraged a trusted partner’s OpenVPN connection, using stolen credentials.

The financially motivated Toy Ghouls group (also tracked as Bearlyfy, Labubu, and Laboo.boo) upgraded its ransomware arsenal with GenieLocker, a custom encryption Trojan active since March 2026. Toy Ghouls previously relied on third-party encryption Trojans including RedAlert, LockBit, and Babuk. 

Toy Ghouls Upgrade Their Ransomware Arsenal

GenieLocker marks a shift to bespoke tooling, cutting the group's dependence on off-the-shelf families, Kaspersky's Securelist reported on July 30. 

The malware runs natively on Windows, Linux, and ESXi, and uses the open-source libsodium library, encrypting file contents with XChaCha20-Poly1305 and protecting file keys via Curve25519-XSalsa20-Poly1305.

GenieLocker help message | Source: Kaspersky's Securelist
GenieLocker help message | Source: Kaspersky's Securelist

Attack Chain and Tradecraft

In a March 2026 incident, the attackers gained initial access through an OpenVPN connection originating from a trusted external partner's network, using stolen but valid credentials. They then deployed the following tools for discovery and credentials, and accessed KeePassXC databases:

Lateral movement used RDP for Windows machines and SSH for Linux servers, while legitimate tools PsExec and PAExec drove the widespread deployment of the encryption Trojan.

Stealth-Focused Impact

GenieLocker drops no ransom note on disk and carries no contact details, forcing operators to deliver demands manually, likely to evade proactive detection. Forensic analysis found no data exfiltration, and Toy Ghouls run no data-leak site or double-extortion model. 

The report says telemetry shows detections mainly in Russia, with the March 2026 campaign focusing on manufacturing, followed by construction, financial services, retail, and technology.

Mimikatz was also used last year by the UAT-5918 threat actor to target critical infrastructure entities in Taiwan.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: