Toy Ghouls is no longer dependent on Windows-only ransomware or a direct endpoint foothold. Its custom GenieLocker family lets one intrusion reach Windows, Linux, and ESXi, so the usual assumption that only desktops need priority protection misses the real blast radius.
Kaspersky says GenieLocker has been active since March 2026 and was used against Russian manufacturing organizations. The group got in through an OpenVPN connection from an external partner’s network using stolen but still valid credentials, then used normal admin tools to move across Windows and Linux systems and encrypt both server and hypervisor environments.
The practical shift is that a trusted partner VPN account can now be the start of a cross-platform encryption event. If defenders still treat ransomware as an endpoint problem, they can miss the Linux and ESXi systems that keep the business running.