From Sabotage to Sophistication: Bearlyfy Targets Russian Enterprises with Custom GenieLocker Ransomware
The pro-Ukrainian threat actor Bearlyfy (Labubu) has escalated its campaign against Russian businesses, deploying a proprietary Windows ransomware strain dubbed GenieLocker to extort and sabotage major enterprises.

A conceptual representation of the Bearlyfy hacking group's impact on Russian corporate infrastructure using custom ransomware.
The landscape of regional cyber conflict has shifted as Bearlyfy (also known as Labubu), a pro-Ukrainian hacking group, matures into a high-tier threat. According to a recent report from security vendor F6, the group has claimed over 70 victims since January 2025, recently moving away from off-the-shelf tools to deploy a custom-built encryptor: GenieLocker.
The Evolution of Bearlyfy
Initially surfacing in early 2025, Bearlyfy was characterized by rapid-fire, less sophisticated attacks using leaked encryptors like LockBit 3.0 and Babuk. However, throughout 2025, the group's tactics evolved significantly:
- Collaboration: Analysts have noted tactical overlaps with PhantomCore and collaborations with Head Mare, both groups known for targeting Russian and Belarusian interests.
- Financial Escalation: Ransom demands have skyrocketed from an initial €80,000 to hundreds of thousands of dollars, with approximately 20% of victims reportedly paying the ransom.
- Hybrid Objectives: The group operates with a dual mandate of financial extortion and pure industrial sabotage.
Technical Deep-Dive: GenieLocker
Since March 2026, Bearlyfy has transitioned to GenieLocker, a proprietary ransomware family targeting Windows endpoints.
- Inspiration: The encryption scheme draws heavy inspiration from the Venus and Trinity ransomware families.
- Initial Access: The group primarily exploits external services and vulnerable applications to drop MeshAgent for remote access.
- Psychological Warfare: Unlike automated systems, Bearlyfy actors often craft manual ransom notes to exert maximum psychological pressure on corporate leadership.
A Growing "Nightmare" for Enterprises
While the group began by targeting small-to-medium businesses, it has now become what F6 describes as a "veritable nightmare" for major Russian enterprises. Their ability to execute swift data encryption with minimal preparation makes them a difficult adversary to intercept before the damage is done.
For organizations operating in the region, the rapid evolution of Bearlyfy serves as a critical reminder of the need for robust vulnerability management and offline backup strategies.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.