Last seven days
- First activity
- Sep 5, 2026
- Last activity
- Sep 5, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Toy Ghouls is a financially motivated ransomware and extortion group active against Russian organizations since at least January 2025.
Profile source: Mallory opens in a new tabToy Ghouls
Toy Ghouls is a financially motivated ransomware and extortion group active against Russian organizations since at least January 2025. It is also tracked as Bearlyfy, Laboo.boo, Labubu, and Feral Wolf. The group has targeted manufacturing most prominently, with reported activity also affecting construction, financial services, retail, and technology organizations.
Toy Ghouls has used LockBit, RedAlert, and Babuk ransomware before developing its own cross-platform GenieLocker ransomware, which targets Windows, Linux, and VMware ESXi environments. GenieLocker can disrupt virtualized infrastructure by stopping virtual machines and encrypting virtual disks. Observed activity supports an encryption-focused extortion model; no data-theft, public leak-site, or double-extortion activity has been established.
Initial access has involved valid stolen credentials, trusted third-party remote-access relationships, exposed services, compromised contractor infrastructure, and insecure server configurations. The group conducts network and host reconnaissance, steals credentials from operating-system credential stores, browser and password-manager data, and Active Directory sources, and uses credential abuse techniques including pass-the-hash, overpass-the-hash, DCSync, and AD CS misconfiguration abuse. It moves laterally through RDP, SSH, remote-management tooling, and remote execution utilities, and deploys ransomware broadly using administrative execution tools.
Toy Ghouls uses reverse SSH tunnels and other proxying tools for command-and-control and remote access. It has established persistence through Windows services, scheduled tasks, and locally created accounts. The group performs defense evasion by clearing event logs, deleting remote-access artifacts and staging archives, modifying firewall configurations, and using anti-debugging and integrity-checking functionality in GenieLocker.
Since July 2026, Toy Ghouls has also deployed custom Windows backdoors, mqtt-bird-agent and matrix-bird-agent. These implants support host telemetry collection, command execution, and service-based persistence. One variant uses MQTT broker infrastructure for command-and-control, while the other communicates using the Matrix protocol through Element-compatible infrastructure. This bespoke tooling reflects an evolution from reliance on publicly available utilities and leaked ransomware builders toward proprietary malware development.
C2 tracking
Derp observations, rolling seven-day window
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.