← Back to Feed

Toy Ghouls’ new toy: the GenieLocker ransomware

July 30, 2026 · Kaspersky (Securelist) · Severity: CRITICAL

Key Takeaways

  • Introduction The new GenieLocker ransomware family has been active since March 2026.
  • It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls g.
  • The Toy Ghouls, also known as Bearlyfy, Labubu and Laboo.boo, is a financially motivated extortion group, which previously relied on third-party encry.
☕ Buy a Coffee