← Back to Feed
Toy Ghouls’ new toy: the GenieLocker ransomware
July 30, 2026 · Kaspersky (Securelist) · Severity: CRITICAL
Key Takeaways
- Introduction The new GenieLocker ransomware family has been active since March 2026.
- It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls g.
- The Toy Ghouls, also known as Bearlyfy, Labubu and Laboo.boo, is a financially motivated extortion group, which previously relied on third-party encry.