Kaspersky experts discovered a new family of custom ransomware variants, dubbed GenieLocker, in attacks attributed to the financially motivated extortion group Toy Ghouls. The malware was found to target Windows, Linux, and ESXi systems, with a focus on exploiting vulnerabilities in the Cisco Webex Meeting and Zoom Video Conferencing platforms. According to the researchers, the GenieLocker ransomware family is unique in its ability to adapt to different operating systems and environments, making it a particularly concerning threat. The malware uses a combination of encryption and social engineering tactics to extort victims, with the attackers seeking to remain anonymous.
GenieLocker is a sophisticated ransomware variant that has been linked to Toy Ghouls, a notorious financially motivated extortion group. The malware was detected in attacks targeting Windows, Linux, and ESXi systems, including vulnerabilities in the Cisco Webex Meeting and Zoom Video Conferencing platforms. Kaspersky researchers found that the GenieLocker ransomware family is highly adaptable, allowing it to operate effectively on various systems and environments. This adaptability makes it a significant threat to organizations and individuals alike.
GenieLocker's tactics, tactics, and procedures (TTPs) are a mix of traditional ransomware tactics and social engineering techniques. The attackers use a combination of encryption and psychological manipulation to extort their victims, often leaving behind a ransom note demanding payment in cryptocurrency. The attackers' goal is to remain anonymous, making it challenging for law enforcement and cybersecurity professionals to track them down.