GenieLocker is a custom ransomware family deployed by the Toy Ghouls threat actor since March 2026, targeting Russian organizations primarily in manufacturing. It features Windows and Linux/ESXi variants using libsodium-based XChaCha20-Poly1305 and Curve25519-XSalsa20-Poly1305 cryptography. The Windows build includes anti-debugging, a secret argument for sandbox evasion, process/service termination, and file exclusion lists. The ESXi/Linux build targets /vmfs/volumes, supports daemonization, and modifies the ESXi welcome message. Unlike typical ransomware, no ransom notes are dropped; attackers deliver demands manually. No data exfiltration was observed, consistent with Toy Ghouls' non-double-extortion model.
GenieLocker
1 post
Toy Ghouls’ new toy: the GenieLocker ransomware