Toy Ghouls’ new toy: the GenieLocker ransomware
2026-07-30T08:51:55Z•6673162485bc3570d8982ae52701d2fa915fe3b293945d9277e6bd4ba1b16dc8
ArcBridgeBitLockerBridgeHeadC2DNS AAAAGenieLockerGoSerpentMSSQLMicrosoft GraphMirage KittenNightLedgerNimbus ManticoreOkoBot cryptocurrency malwareưở?Project CAV3RNRDPRMMSmoke SandstormStowaway RATToy GhoulsUNC1549ViPNetdata exfiltrationransomwaresupply-chain attackweb shells
What happened
Kaspersky Securelist threat-intelligence updates covering ransomware, espionage, malware campaigns, phishing, industrial threats, and extortion activity. Key topics include GenieLocker ransomware targeting Windows, Linux, and ESXi; Mirage Kitten tools; BitLocker-based extortion; Project CAV3RN covert C2 via Outlook and DNS AAAA records; ViPNet supply-chain abuse; GoSerpent data theft; OkoBot cryptocurrency targeting; device-code phishing; and Armored Likho’s BusySnake Stealer campaign. No CVEs are explicitly identified in the supplied document.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 6673162485bc3570d8982ae52701d2fa915fe3b293945d9277e6bd4ba1b16dc8
- Enrichment time
- 2026-07-30T08:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.