CARDS
CARDS
Genesis is a cybercriminal group that emerged in October 2025, rapidly establishing itself as a significant player in digital extortion. This group is distinct from the Genesis Market, a separate marketplace for stolen credentials that was dismantled in 2023. Genesis ransomware group's primary motivation is financial gain, achieved through a unique double extortion model that focuses predominantly on data exfiltration and public leaks rather than encrypting victim systems. This strategic emphasis on public exposure of sensitive data to exert financial and reputational pressure on victims sets them apart from many traditional ransomware operations. Their rapid appearance and organized operational structure suggest the involvement of experienced threat actors, potentially from other cybercriminal entities.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Associated Activity1
ATT&CK IDs1
Campaign Context
No source-backed campaign or named operation association is currently retained for this actor card. Related campaign rows will appear here when SOCRadar, MITRE ATT&CK Campaigns, Microsoft, Google/Mandiant, CrowdStrike, CISA, or another retained public source ties the actor to a named campaign or operation.
Indicators
39 IOCs are reported by SOCRadar, but the underlying observable values are not yet retained in IntelliOS. The profile therefore cites the source count without republishing unstored IOC values.
Source coverage: 1 source group tracked; 0 currently contribute retained observable or context rows.
Retained Public Observables1,2
39 IOCs are reported by SOCRadar, but the underlying observable values are not yet retained in IntelliOS. The profile therefore cites the source count without republishing unstored IOC values.
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 39 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Genesis | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Genesis | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/genesis | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Genesis.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |