Ransomware Intelligence

genesis

Ransomware group profile

93Victims
RussiaSource country
80Impact score

Description

Genesis is a ransomware group that surfaced in late 2025, known for its focus on data exfiltration and public leaks instead of purely data encryption. They employ a double extortion strategy, targeting organizations with sensitive or regulated data while evading indiscriminate mass attacks. This group's emergence suggests the involvement of highly skilled actors from other cybercriminal circles, motivated primarily by financial gain through extortion activities.

Key insights

  • Utilizes phishing and stolen credentials for initial access to networks.
  • Employed double extortion tactics, threatening to publish stolen data if ransoms are not paid.
  • Targets organizations with sensitive data, particularly in finance and health sectors.
  • Exploits unpatched remote access services and uses infostealer malware for credential harvesting.
  • Has a dedicated dark web leak site for publishing victim information.
  • Implements strong encryption and disables backups during attacks.

Threat Level & Status Breakdown

For genesis · Based on incidents in selected period

3.5threat level
Aggressiveness7/ 10
Lethality0/ 10
Criticality3.6/ 10

Status Breakdown

Claimed100.0%93
First seenAug 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 18, 2026

Recent activity

Monthly attack count for genesis in the selected period

93Total attacks
21peak in May
8.5avg / month
↑ 3 vs first month
AugSepOctNovDecJanFebMarAprMayJun06121824

Intelligence

IOCs, YARA/Sigma rules, and related families for genesis

  1. 6fd538e4a8e3493dda6f9fcdc96e814bdd14f3e2ef8aa46f0143bff34b882c1b
  2. 23094d64721a279c0ce637584b87d6f1
  3. 0893797cae008270ff613b47769e6eb22564184c0121e3bec8ee1769e2da688a
  4. 4871816be6a1128d2cf2f516788a6b8bc39b0d60
  5. 1a5c12ad81440e25dca1eee86fd2f012dd18e2667d21ca64ae7134304e7022f0
View full IOC feed21 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for genesis

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1021

T1021

T1562

T1562

T1040

T1040

T1080

T1080

T1059

T1059

T1609

T1609

T1027

T1027

Victims(93)

CompanyDomainCountryIndustryStatusDiscovered
United Personnel (a division of Masis Staffing Solutions)msastaffing.orgUS United StatesProfessional Services
Claimed
2 days ago
The Associated Builders and Contractors of Indiana/Kentuckyabcindianakentucky.orgUS United StatesOther
Claimed
2 days ago
*B*cavalierflooring.comCN ChinaTransportation
Claimed
13 days ago
PB White & CoUS United StatesProfessional Services
Claimed
16 days ago
Family Medical Associates of RaleighUS United StatesHealthcare
Claimed
16 days ago
Wentworthwentworthstudio.comUS United StatesOther
Claimed
20 days ago
Cavalier Flooring Systems Inc.cavalierflooring.comUS United StatesManufacturing
Claimed
20 days ago
A Roettgersarc-rci.comUS United StatesProfessional Services
Claimed
20 days ago
Green Resourcegreen-resource.comUS United StatesEnergy & Utilities
Claimed
20 days ago
Cedar Street Capital (A part of a Cynvestors Limited Partnership)cedarstreetcapital.comUS United StatesFinancial Services
Claimed
20 days ago
******** & CoUS United StatesFinancial Services
Claimed
21 days ago
*M**US United StatesHealthcare
Claimed
21 days ago
Peña & BrombergUS United StatesProfessional Services
Claimed
22 days ago
**** & ********US United StatesManufacturing
Claimed
28 days ago
Pequod Associatespequodassociates.comUS United StatesOther
Claimed
about 1 month ago
HostBooks (HOT!)hostbooks.comUS United StatesProfessional Services
Claimed
about 1 month ago
Palopalo.usUS United StatesTechnology
Claimed
about 1 month ago
Ben F. Barcus and associates pllcUS United StatesProfessional Services
Claimed
about 1 month ago
Integrated Process Engineers & Constructors.ipec-inc.comUS United StatesProfessional Services
Claimed
about 1 month ago
Rain Makers Solutionsrainmakerssolutions.comUS United StatesProfessional Services
Claimed
about 1 month ago

Page 1 of 5