Genesis
Genesis is a ransomware and data-extortion threat group that emerged in late 2025 and has since claimed intrusions primarily affecting organizations in the United States.
Profile source: Mallory opens in a new tabGenesis
Family profile
Genesis is a ransomware and data-extortion threat group that emerged in late 2025 and has since claimed intrusions primarily affecting organizations in the United States. Reported victims span healthcare, legal, construction, staffing, financial services, technology, agriculture, real estate, and nonprofit sectors, indicating broad opportunistic targeting rather than a narrowly specialized victim profile. Publicly associated incidents include attacks against medical providers, business services firms, trade associations, and nonprofits, including a claimed attack on the National Association on Drug Abuse Programs.
Genesis operates as a conventional ransomware actor, combining data theft with encryption and using a leak site to pressure victims. The group publicly claims responsibility for attacks, alleges exfiltration of victim data, and uses the threat of publishing stolen information to coerce payment. Reported victim notifications and public claims indicate that Genesis seeks both restoration-related ransom payments and payment in exchange for deleting stolen data.
Available reporting supports characterization of Genesis as a relatively new criminal ransomware operation rather than a nation-state actor. High-confidence public information on its internal structure, operators, geographic base, affiliate model, malware lineage, or stable sub-groups is currently not available. No widely used aliases beyond the name Genesis are established in the available information.
Operational record
Recent claims
MITRE ATT&CK