Executive Summary
In March 2026, the pro-Ukrainian hacking group Bearlyfy, also known as Labubu, launched over 70 cyberattacks against Russian companies, primarily targeting the manufacturing sector. The group deployed a custom-built Windows ransomware strain named GenieLocker, marking a significant evolution from their previous use of third-party encryptors like LockBit 3 and Babuk. These attacks involved exploiting external services and vulnerable applications to gain access, followed by the deployment of tools such as MeshAgent for remote access and encryption. Ransom demands escalated to hundreds of thousands of dollars, with approximately 20% of victims reportedly paying. (thehackernews.com)
This incident underscores the increasing sophistication and boldness of hacktivist groups in leveraging custom malware to achieve both financial gain and strategic sabotage. The development and deployment of proprietary ransomware like GenieLocker highlight a trend where threat actors are investing in bespoke tools to enhance their operational effectiveness and evade detection. (thehackernews.com)
Why This Matters Now
The emergence of custom ransomware like GenieLocker signifies a shift in the threat landscape, where hacktivist groups are developing tailored tools to maximize impact. This trend necessitates heightened vigilance and adaptive cybersecurity measures to counter increasingly sophisticated and targeted attacks.
Attack Path Analysis
The attackers gained initial access by exploiting a trusted relationship with an external partner, using stolen credentials to connect via OpenVPN. After breaching the network, they installed tools like Mimikatz to extract credentials and SoftPerfect Network Scanner for discovery. They moved laterally using RDP and SSH, deploying the GenieLocker ransomware across Windows, Linux, and ESXi systems. A reverse SSH tunnel was established for command and control. No evidence of data exfiltration was found. The attack culminated in the encryption of files and virtual machine disks, disrupting operations.
Kill Chain Progression
Initial Compromise
Description
The attackers exploited a trusted relationship with an external partner, using stolen credentials to gain access via OpenVPN.
MITRE ATT&CK® Techniques
Valid Accounts
External Remote Services
Account Discovery
OS Credential Dumping
Remote Services
System Services
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Authentication
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Manufacturing
Primary target of GenieLocker ransomware campaign with critical exposure to Windows/Linux/ESXi encryption, lateral movement threats, and operational technology compromise requiring enhanced segmentation.
Construction
Secondary target experiencing GenieLocker attacks with vulnerabilities in hybrid cloud environments, VPN compromises, and inadequate east-west traffic monitoring enabling credential theft.
Financial Services
High-value target facing multi-platform ransomware threats requiring zero trust architecture, encrypted traffic inspection, and enhanced egress filtering to prevent data exfiltration.
Information Technology/IT
Critical infrastructure sector vulnerable to custom ransomware targeting virtualized environments, requiring Kubernetes security, cloud firewall protection, and anomaly detection capabilities.
Sources
- Toy Ghouls’ new toy: the GenieLocker ransomwarehttps://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/Verified
- APT and financial attacks on industrial organizations in Q1 2026 – Kaspersky ICS CERT ENhttps://ics-cert.kaspersky.com/publications/reports/2026/05/21/apt-and-financial-attacks-on-industrial-organizations-in-q1-2026/Verified
- «Вас посетил лабубу»: шифровальщики Toy Ghouls атакуют российские организации через подрядчиковhttps://www.kaspersky.ru/about/press-releases/vas-posetil-labubu-shifrovalshiki-toy-ghouls-atakuyut-rossijskie-organizacii-cherez-podryadchikovVerified
- Bearlyfy Hits 70+ Russian Firms with Custom GenieLocker Ransomwarehttps://www.hendryadrian.com/bearlyfy-hits-70-russian-firms-with-custom-genielocker-ransomware/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's lateral movement and limited the blast radius by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to access internal resources would likely be limited, reducing the potential for unauthorized entry.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges and access sensitive areas would likely be constrained, limiting their operational scope.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement across systems would likely be restricted, reducing the spread of ransomware.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command-and-control channels would likely be hindered, disrupting their operations.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data would likely be restricted, reducing the risk of data loss.
The attacker's ability to cause widespread operational disruption would likely be limited, reducing the overall impact.
Impact at a Glance
Affected Business Functions
- Manufacturing Operations
- Supply Chain Management
- Product Design and Development
Estimated downtime: 14 days
Estimated loss: $500,000
Potential exposure of proprietary manufacturing processes, supply chain details, and product designs.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement.
- • Deploy East-West Traffic Security to monitor and control internal traffic, detecting unauthorized movements.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights across cloud environments and detect anomalies.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent unauthorized data transfers.
- • Apply Threat Detection & Anomaly Response to identify and respond to suspicious activities promptly.



