Bearlyfy
0 incidentes
0 paises
0 sectores
apt UA Ultimo: -
Aliases: Labubu
Bearlyfy is a pro-Ukrainian ransomware group that emerged in January 2025, evolving from targeting smaller Russian businesses with modest demands and leaked ransomware tools to engaging larger enterprises with proprietary ransomware and escalated ransom demands. The group's primary motivation is a dual blend of financial extortion and political sabotage against Russian organizations, aiming to inflict maximum damage while also generating revenue. A unique characteristic setting Bearlyfy apart is its practice of manually crafting ransom notes for victims, often including messages that mock the target company, rather than relying on automated generation. The group has demonstrated a notable evolution in its operational model, transitioning from reliance on readily available tools to deploying its own custom-developed ransomware, GenieLocker, showcasing increasing technical maturity and a more structured approach to cyber operations. Some security vendors have also tracked the group under