Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Toy Ghouls’ new toy: the GenieLocker ransomware

Cross-platform ransomware GenieLocker targets Windows, Linux, and ESXi simultaneously — raising the stakes for organisations relying on VMware virtualisation without isolated backup strategies.

Summary written by editorial AI · Source link below

Filed by Securelist (Kaspersky)1 min readRead at source ↗

Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.

Editorial Analysis

Why it matters

Multi-platform ransomware families compress the window between initial compromise and total environment encryption, making isolated backups and hypervisor-layer monitoring critical.

What to do

Ensure ESXi hosts are included in ransomware tabletop exercises and that immutable backup copies exist for all three OS families.

Board brief

A new ransomware strain encrypts Windows, Linux, and VMware environments in parallel, increasing the risk of full-stack outages.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Securelist (Kaspersky)

External link — opens at Securelist (Kaspersky) in a new tab.

§
Continue with

More from the Threat Intel Desk