Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationhacktivist-operationinitial-access-methodstate-sponsored-disruption

Bearlyfy deploys GenieLocker in ransomware campaign against Russian companies

Updated 3mo agoFirst seen Mar 26, 20262 sources

The pro-Ukrainian hacker group Bearlyfy has carried out more than 70 attacks against Russian companies, escalating from smaller intrusions and modest ransom demands into a broader campaign combining extortion with sabotage. Russian cybersecurity firm F6 said the group, active since January 2025 and also tracked as Labubu, initially relied on leaked ransomware code including LockBit 3 Black, Babuk for Linux, and a modified PolyVice variant before shifting in March to a custom Windows strain called GenieLocker.

F6 said Bearlyfy typically gained access through exposed external services and vulnerable applications, then used tools such as MeshAgent for remote access and to support encryption or destructive activity. Researchers also reported cooperation with the pro-Ukrainian group Head Mare and tooling or infrastructure overlaps with PhantomCore, suggesting ties to a wider ecosystem targeting Russian and Belarusian organizations. The group’s ransom demands reportedly rose from about €80,000 to several hundred thousand dollars, with roughly one in five victims paying, as Bearlyfy expanded from smaller businesses to larger Russian enterprises.

Share:
Bearlyfy deploys GenieLocker in ransomware campaign against Russian companies
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 26, 20263mo ago

F6 attributes more than 70 attacks to Bearlyfy

By late March 2026, Russian cybersecurity firm F6 said Bearlyfy had carried out more than 70 cyberattacks against Russian companies over the previous year. F6 assessed the group as having evolved into a serious threat to larger Russian enterprises, with ransom demands rising from about €80,000 to hundreds of thousands of dollars.

Mar 1, 20264mo ago

Bearlyfy deploys custom GenieLocker ransomware

Since early March 2026, Bearlyfy has used a custom Windows ransomware strain called GenieLocker, which F6 believes the group developed itself. The shift marked an escalation from using leaked code to operating its own ransomware for encryption and destructive attacks.

Jan 1, 20251y ago

Bearlyfy collaborates with Head Mare and shows infrastructure overlaps

F6 observed cooperation between Bearlyfy and the pro-Ukrainian group Head Mare, while also identifying tooling and infrastructure overlaps with PhantomCore. These findings linked Bearlyfy to a broader pro-Ukrainian threat ecosystem targeting Russian and Belarusian entities.

Bearlyfy conducts early attacks using leaked ransomware code

In its earlier operations during 2025 and before March 2026, Bearlyfy relied on leaked or modified ransomware families including LockBit 3 Black, Babuk for Linux systems, and later a modified PolyVice variant. F6 said the group commonly gained access through exposed external services and vulnerable applications, then used tools such as MeshAgent for remote access and attack execution.

Bearlyfy emerges and begins targeting Russian companies

According to F6, the pro-Ukrainian group Bearlyfy, also known as Labubu, emerged in January 2025 and started attacking Russian organizations. Its early victims were primarily smaller businesses, and the group paired political sabotage goals with ransomware extortion.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Affected products
3 linked
WindowsIphoneLinux
Organizations
2 linked
F6Apple
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.