Bearlyfy is known for targeting Russian companies since January 2025 using GenieLocker ransomware and a modified PolyVice tool.
Analyst brief
Bearlyfy is a threat actor that has conducted over 70 cyber attacks on Russian companies since January 2025, driven by extortion and sabotage objectives. It targets Russian organizations, leveraging vulnerabilities in external services and applications for initial access. Key TTPs include deploying a custom ransomware strain called GenieLocker and a modified version of the PolyVice tool. Defenders should focus on promptly patching external-facing vulnerabilities and ensuring robust, immutable backup strategies to mitigate ransomware impact.
Bearlyfy
Labubu
unknown
Bearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a custom Windows ransomware strain known as GenieLocker. The group operates with dual objectives of extortion and sabotage, utilizing a modified version of PolyVice and leveraging vulnerabilities in external services and applications for initial access. Analysis reveals overlaps with PhantomCore, indicating a pro-Ukrainian interest, while Bearlyfy's attacks are characterized by minimal preparation and a focus on immediate impact through data encryption and destruction. Approximately 20% of victims reportedly pay the ransom, with demands escalating to hundreds of thousands of dollars.