HomeSecurityBearlyfy targets Russian companies with GenieLocker ransomware

Bearlyfy targets Russian companies with the GenieLocker ransomware

Bearlyfy ,a pro-Ukrainian hacker group, has carried out more than 70 cyberattacks against Russian companies (since January 2025), using a custom Windows ransomware codenamed GenieLocker. The group, also known as Labubu, has evolved from simple attacks on small businesses to sophisticated cyberattacks that combine extortion with sabotage.

Bearlyfy GenieLocker ransomware

According to Russian cybersecurity firm F6 , Bearlyfy operates as a dual-purpose group aimed at causing maximum damage to Russian businesses. Its attacks serve both financial extortion and political sabotage goals , reflecting the escalation of cyberattacks against Russia following the invasion of Ukraine in 2022.

The group was first detected by F6 in September 2025, when it was using encryptors associated with LockBit 3 (Black) and Babuk . Initially, the attacks focused on smaller companies, but gradually escalated with ransom demands reaching €80,000 (approximately $92,100 ). By August 2025, the group had claimed responsibility for at least 30 victims .

See also: Interlock Ransomware: Cisco FMC Zero-Day Exploit

Since May 2025, Bearlyfy perpetrators have been using a modified version of PolyVice , a ransomware family attributed to Vice Society (also known as DEV-0832 or Vanilla Tempest ). This group has a history of delivering third-party lockers such as Hello Kitty , Zeppelin , RedAlert , and Rhysida ransomware in their attacks.

Connections with PhantomCore and evolution of Bearlyfy

Further analysis of the group’s toolkit and infrastructure reveals overlaps with PhantomCore, another group believed to be operating with Ukrainian interests. PhantomCore is known for attacks against Russian and Belarusian companies since 2022. Bearlyfy reported to have collaborated with Head Mare.

Bearlyfy targets Russian companies with the GenieLocker ransomware

The group's attacks begin by exploiting external services and vulnerable applications , followed by installing tools like MeshAgent to facilitate remote access and allow data encryption, destruction, or modification. In contrast, PhantomCore conducts APT-style campaigns , where identification, persistence, and data extraction are prioritized.

See also: LeakNet Ransomware group uses ClickFix techniques

As F6 noted last year, “the group is distinguished by rapid attacks characterized by minimal preparation and rapid data encryption. Another characteristic of these attacks is that the ransom notes are not generated by the ransomware itself, but instead are created directly by the attackers.”

GenieLocker: The new custom ransomware of Bearlyfy

The most notable change in the group's modus operandi is the use of a proprietary ransomware family called GenieLocker to target Windows endpoints . GenieLocker 's encryption scheme is similar to that of the Venus/Trinity ransomware .

One of the characteristics of ransomware attacks is that ransom notes are not automatically generated by the locker. Instead, the perpetrators choose their own methods to share next steps with victims, either by providing simple contact information or sending complex messages that seek to exert psychological pressure and force them to pay.

According to The HackerNews, Bearlyfy's attacks have proven to be an illegal source of revenue. According to data from F6, about one in five victims chooses to pay the ransom. Ransom demands are said to have increased, reaching hundreds of thousands of dollars.

See also: Advanced Custom Fields: Extended WordPress – Serious vulnerability

Bearlyfy targets Russian companies with the GenieLocker ransomware

The rise of Bearlyfy coincides with a broader increase in cyber attacks against Russia, after the invasion of Ukraine in 2022.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

As F6 stated : “ While in the early stages, members Bearlyfy showed a lack of sophisticated techniques and were clearly experimenting with various techniques and tools, within a year, this group has developed into a real nightmare for Russian businesses – including large enterprises .”

To protect against such threats, experts recommend implementing multiple layers of security, including regular software updates, using multi-factor authentication (MFA) , and deploying endpoint detection and response (EDR) to detect custom malware like GenieLocker. Maintaining offline backups and implementing zero-trust are also critical to limiting lateral movement.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS