UA

BearlyfyBearlyfy

Also known as: Labubu · Bearlyfy

Origin
UA
Known aliases
2

Profile

Bearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a custom Windows ransomware strain known as GenieLocker. The group operates with dual objectives of extortion and sabotage, utilizing a modified version of PolyVice and leveraging vulnerabilities in external services and applications for initial access. Analysis reveals overlaps with PhantomCore, indicating a pro-Ukrainian interest, while Bearlyfy's attacks are characterized by minimal preparation and a focus on immediate impact through data encryption and destruction. Approximately 20% of victims reportedly pay the ransom, with demands escalating to hundreds of thousands of dollars.

Aliases· 2

LabubuBearlyfy

References

  1. https://therecord.media/ransomware-ukraine-russia-bearlyfy
  2. https://www.f6.ru/blog/bearlyfy/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
SpaceBears
Actor
ENERGETIC BEAR
Software
Egalyty
Software
Lockify
Actor
LofyGang
Actor
Boulder Bear
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.