HomeIntelligenceBrief
BREACH BRIEF🟠 High Ransomware

Bearlyfy Deploys Custom GenieLocker Ransomware Against 70+ Russian Companies

Pro‑Ukrainian group Bearlyfy has leveraged a bespoke ransomware tool, GenieLocker, to encrypt systems at over 70 Russian firms. The campaign underscores the risk of geopolitically motivated ransomware that can disrupt supply‑chain partners and expose third‑party risk.

LiveThreat™ Intelligence · 📅 March 27, 2026· 📰 thehackernews.com
🟠
Severity
High
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Bearlyfy Deploys Custom GenieLocker Ransomware Against 70+ Russian Companies

What Happened – The pro‑Ukrainian threat group Bearlyfy (aka Labubu) has been linked to more than 70 ransomware incidents targeting Russian enterprises since its emergence in early 2025. The latest wave uses a bespoke Windows ransomware strain dubbed GenieLocker, which encrypts victim data and demands payment for decryption keys.

Why It Matters for TPRM

  • Ransomware attacks on third‑party vendors can cascade to downstream customers, disrupting supply‑chain operations.
  • The use of a custom ransomware family indicates a high level of technical capability and intent to cause maximum operational impact.
  • Geopolitical motivation raises the likelihood of targeted, persistent campaigns against specific industry verticals.

Who Is Affected – Russian‑based firms across multiple sectors (technology, manufacturing, services) that rely on third‑party software or managed services.

Recommended Actions

  • Review any contracts or data flows with Russian‑origin vendors to assess exposure.
  • Verify that affected vendors have robust ransomware response plans, offline backups, and network segmentation.
  • Increase monitoring for anomalous encryption activity and enforce multi‑factor authentication on privileged accounts.

Technical Notes – The attack vector has not been publicly disclosed; however, initial indicators point to phishing‑based credential compromise and exploitation of unpatched Windows systems. No specific CVEs have been cited. Data encrypted includes file systems, databases, and potentially backup repositories. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/03/bearlyfy-hits-70-russian-firms-with.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →