Skip to content

Toy Ghouls

Toy Ghouls is a financially motivated ransomware and extortion group active against Russian organizations since at least January 2025.

Profile source: Mallory opens in a new tab

Toy Ghouls

Family profile

Toy Ghouls is a financially motivated ransomware and extortion group active against Russian organizations since at least January 2025. It is also tracked as Bearlyfy, Laboo.boo, Labubu, and Feral Wolf. The group has targeted manufacturing most prominently, with reported activity also affecting construction, financial services, retail, and technology organizations.

Toy Ghouls has used LockBit, RedAlert, and Babuk ransomware before developing its own cross-platform GenieLocker ransomware, which targets Windows, Linux, and VMware ESXi environments. GenieLocker can disrupt virtualized infrastructure by stopping virtual machines and encrypting virtual disks. Observed activity supports an encryption-focused extortion model; no data-theft, public leak-site, or double-extortion activity has been established.

Initial access has involved valid stolen credentials, trusted third-party remote-access relationships, exposed services, compromised contractor infrastructure, and insecure server configurations. The group conducts network and host reconnaissance, steals credentials from operating-system credential stores, browser and password-manager data, and Active Directory sources, and uses credential abuse techniques including pass-the-hash, overpass-the-hash, DCSync, and AD CS misconfiguration abuse. It moves laterally through RDP, SSH, remote-management tooling, and remote execution utilities, and deploys ransomware broadly using administrative execution tools.

Toy Ghouls uses reverse SSH tunnels and other proxying tools for command-and-control and remote access. It has established persistence through Windows services, scheduled tasks, and locally created accounts. The group performs defense evasion by clearing event logs, deleting remote-access artifacts and staging archives, modifying firewall configurations, and using anti-debugging and integrity-checking functionality in GenieLocker.

Since July 2026, Toy Ghouls has also deployed custom Windows backdoors, mqtt-bird-agent and matrix-bird-agent. These implants support host telemetry collection, command execution, and service-based persistence. One variant uses MQTT broker infrastructure for command-and-control, while the other communicates using the Matrix protocol through Element-compatible infrastructure. This bespoke tooling reflects an evolution from reliance on publicly available utilities and leaked ransomware builders toward proprietary malware development.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 5, 2026
Last activity
Sep 5, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

MITRE ATT&CK

Toy Ghouls in ATT&CK

58 distinct techniques

Techniques

58 techniques
T1102.002 Bidirectional Communication T1102 Web Service T1082 System Information Discovery T1059.001 PowerShell T1027 Obfuscated Files or Information T1614 System Location Discovery T1059.003 Windows Command Shell T1070.004 File Deletion T1071.004 DNS T1021.006 Windows Remote Management T1016.001 Internet Connection Discovery T1112 Modify Registry T1543.003 Windows Service T1003.003 NTDS T1550.002 Pass the Hash T1489 Service Stop T1090.002 External Proxy T1059 Command and Scripting Interpreter T1021.002 SMB/Windows Admin Shares T1218.007 Msiexec T1003.001 LSASS Memory T1003.006 DCSync T1649 Steal or Forge Authentication Certificates T1555 Credentials from Password Stores T1053.005 Scheduled Task T1049 System Network Connections Discovery T1105 Ingress Tool Transfer T1136.001 Local Account T1490 Inhibit System Recovery T1219 Remote Access Tools T1486 Data Encrypted for Impact T1021.001 Remote Desktop Protocol T1218.003 CMSTP T1070.001 Clear Windows Event Logs T1562.004 Disable or Modify System Firewall T1078 Valid Accounts T1555.003 Credentials from Web Browsers T1046 Network Service Discovery T1497.001 System Checks T1190 Exploit Public-Facing Application T1069.002 Domain Groups T1133 External Remote Services T1003.002 Security Account Manager T1071 Application Layer Protocol T1016 System Network Configuration Discovery T1564.003 Hidden Window T1562.001 Disable or Modify Tools T1497 Virtualization/Sandbox Evasion T1543 Create or Modify System Process T1003 OS Credential Dumping T1021.004 SSH T1572 Protocol Tunneling T1569.002 Service Execution T1570 Lateral Tool Transfer T1563.002 RDP Hijacking T1090 Proxy T1090.003 Multi-hop Proxy T1021 Remote Services

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.