Ransomware Intelligence

genesis

Ransomware group profile

88Victims
RussiaSource country
80Impact score

Description

Genesis is a ransomware group that surfaced in late 2025, known for its focus on data exfiltration and public leaks instead of purely data encryption. They employ a double extortion strategy, targeting organizations with sensitive or regulated data while evading indiscriminate mass attacks. This group's emergence suggests the involvement of highly skilled actors from other cybercriminal circles, motivated primarily by financial gain through extortion activities.

Key insights

  • Utilizes phishing and stolen credentials for initial access to networks.
  • Employed double extortion tactics, threatening to publish stolen data if ransoms are not paid.
  • Targets organizations with sensitive data, particularly in finance and health sectors.
  • Exploits unpatched remote access services and uses infostealer malware for credential harvesting.
  • Has a dedicated dark web leak site for publishing victim information.
  • Implements strong encryption and disables backups during attacks.

Threat Level & Status Breakdown

For genesis · Based on incidents in selected period

4.6threat level
Aggressiveness10/ 10
Lethality0/ 10
Criticality3.6/ 10

Status Breakdown

Claimed100.0%88
First seenAug 2025
Last seenMay 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for genesis in the selected period

88Total attacks
21peak in May
8.8avg / month
↑ 19 vs first month
AugSepOctNovDecJanFebMarAprMay06121824

Intelligence

IOCs, YARA/Sigma rules, and related families for genesis

  1. 6fd538e4a8e3493dda6f9fcdc96e814bdd14f3e2ef8aa46f0143bff34b882c1b
  2. 534b2707937c2ed87e53f8951b9167026e3d9d3cfa98f00ac38487d68d730fb5
  3. 23094d64721a279c0ce637584b87d6f1
  4. 0893797cae008270ff613b47769e6eb22564184c0121e3bec8ee1769e2da688a
  5. 4871816be6a1128d2cf2f516788a6b8bc39b0d60
  6. 1a5c12ad81440e25dca1eee86fd2f012dd18e2667d21ca64ae7134304e7022f0
View full IOC feed23 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for genesis

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1021

T1021

T1562

T1562

T1040

T1040

T1080

T1080

T1059

T1059

T1609

T1609

T1027

T1027

Victims(88)

CompanyDomainCountryIndustryStatusDiscovered
Cedar Street Capital (A part of a Cynvestors Limited Partnership)cedarstreetcapital.comUS United StatesFinancial Services
Claimed
4 days ago
Wentworthwentworthstudio.comUS United StatesOther
Claimed
4 days ago
Cavalier Flooring Systems Inc.cavalierflooring.comUS United StatesManufacturing
Claimed
4 days ago
A Roettgersarc-rci.comUS United StatesProfessional Services
Claimed
4 days ago
Green Resourcegreen-resource.comUS United StatesEnergy & Utilities
Claimed
4 days ago
******** & CoUS United StatesFinancial Services
Claimed
5 days ago
*M**US United StatesHealthcare
Claimed
5 days ago
Peña & BrombergUS United StatesProfessional Services
Claimed
6 days ago
**** & ********US United StatesManufacturing
Claimed
12 days ago
Pequod Associatespequodassociates.comUS United StatesOther
Claimed
23 days ago
HostBooks (HOT!)US United StatesProfessional Services
Claimed
23 days ago
Ben F. Barcus and associates pllcUS United StatesProfessional Services
Claimed
23 days ago
Palopalo.usUS United StatesTechnology
Claimed
23 days ago
Casino Gaming CommissionJM JamaicaGovernment & Defense
Claimed
23 days ago
Fargo Moorhead West Fargo ChamberUS United StatesProfessional Services
Claimed
23 days ago
Integrated Process Engineers & Constructors.US United StatesProfessional Services
Claimed
23 days ago
Prescott & Holdenfamilylaw.comUS United StatesProfessional Services
Claimed
25 days ago
Van Atta Engineeringvae.ccUS United StatesManufacturing
Claimed
25 days ago
CarePoint Healthcarepointhealth.caCA CanadaHealthcare
Claimed
25 days ago
The American Board of Preventive Medicinetheabpm.orgUS United StatesHealthcare
Claimed
25 days ago

Page 1 of 5