Uptime Hamster: 10d 4h 38mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Bearlyfy

Bearlyfy

0 incidentes 0 paises 0 sectores apt UA Ultimo: -
Aliases: Labubu
Ver en IntelTracker → APTTrail →
Bearlyfy is a pro-Ukrainian ransomware group that emerged in January 2025, evolving from targeting smaller Russian businesses with modest demands and leaked ransomware tools to engaging larger enterprises with proprietary ransomware and escalated ransom demands. The group's primary motivation is a dual blend of financial extortion and political sabotage against Russian organizations, aiming to inflict maximum damage while also generating revenue. A unique characteristic setting Bearlyfy apart is its practice of manually crafting ransom notes for victims, often including messages that mock the target company, rather than relying on automated generation. The group has demonstrated a notable evolution in its operational model, transitioning from reliance on readily available tools to deploying its own custom-developed ransomware, GenieLocker, showcasing increasing technical maturity and a more structured approach to cyber operations. Some security vendors have also tracked the group under

Aliases del actor

Labubu

Actores similares

APT29 (Cozy Bear)actor · 1Saint Bearactor · 1energetic-bearactor · 1ember-bearactor · 1Energetic Bearapt · 0Boulder Bearapt · 0Pat Bearapt · 0White Bearapt · 0
Tipo
apt
Pais origen
UA
Motivacion
-
Impacto
8
Actualizado
Fri, 10 Ap