Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

genesis Ransomware Group

Ransomware group profile

100Victims
RussiaSource country
80Impact score

Description

Genesis is a ransomware group that surfaced in late 2025, known for its focus on data exfiltration and public leaks instead of purely data encryption. They employ a double extortion strategy, targeting organizations with sensitive or regulated data while evading indiscriminate mass attacks. This group's emergence suggests the involvement of highly skilled actors from other cybercriminal circles, motivated primarily by financial gain through extortion activities.

Key insights

  • Utilizes phishing and stolen credentials for initial access to networks.
  • Employed double extortion tactics, threatening to publish stolen data if ransoms are not paid.
  • Targets organizations with sensitive data, particularly in finance and health sectors.
  • Exploits unpatched remote access services and uses infostealer malware for credential harvesting.
  • Has a dedicated dark web leak site for publishing victim information.
  • Implements strong encryption and disables backups during attacks.

Threat Level & Status Breakdown

For genesis · Based on incidents in selected period

3.6threat level
Aggressiveness7/ 10
Lethality0/ 10
Criticality3.7/ 10

Status Breakdown

Claimed100.0%100
First seenSep 2025
Last seenSep 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedSep 17, 2026

Recent activity

Monthly attack count for genesis in the selected period

100Total attacks
18peak in May
7.7avg / month
SepOctNovDecJanFebMarAprMayJunJulAugSep05101520

Intelligence

IOCs, YARA/Sigma rules, and related families for genesis

  1. 1a5c12ad81440e25dca1eee86fd2f012dd18e2667d21ca64ae7134304e7022f0
  2. 76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235d
  3. 6fd538e4a8e3493dda6f9fcdc96e814bdd14f3e2ef8aa46f0143bff34b882c1b
  4. 23094d64721a279c0ce637584b87d6f1
  5. 4871816be6a1128d2cf2f516788a6b8bc39b0d60
  6. 430a73bc2a01dd1c5c84c5cc8bf0c65b
View full IOC feed36 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for genesis

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1021

T1021

T1562

T1562

T1040

T1040

T1080

T1080

T1059

T1059

T1609

T1609

T1027

T1027

Victims(99)

United StatesFinancial Services
Claimed
4 days ago
United StatesProfessional Services
Claimed
4 days ago
United StatesHealthcarehher24.com
Claimed
26 days ago
United StatesHealthcareinterimhealthcare.com
Claimed
about 1 month ago
United StatesHealthcareinterimhealthcare.com
Claimed
about 1 month ago
United StatesHealthcare
Claimed
about 1 month ago
DenmarkTechnologyboyum-it.com
Claimed
about 2 months ago
United StatesManufacturingcawalkerconstruction.com
Claimed
about 2 months ago
United StatesManufacturinginfinitypipeinc.com
Claimed
about 2 months ago
United StatesManufacturing
Claimed
about 2 months ago
United StatesTechnologyservonix.com
Claimed
about 2 months ago
United StatesRetail & E-Commercewestlake-realty.com
Claimed
about 2 months ago
CanadaProfessional Servicesbramptondirect.ca
Claimed
about 2 months ago
United StatesOtherwestgatellc.com
Claimed
2 months ago
United StatesProfessional Servicesdunaganassociates.com
Claimed
2 months ago
United StatesTechnologybri-tech.com
Claimed
2 months ago
United StatesHealthcaremirageendoscopycenter.com
Claimed
2 months ago
United StatesTechnologysbigrower.com
Claimed
2 months ago
United StatesTechnologysinyc.com
Claimed
2 months ago
United StatesOtherdicon.com
Claimed
2 months ago

Page 1 of 5