Ransomware Intelligence

global

Ransomware group profile

30Victims
RussiaSource country
83Impact score
Also Known As
global ransomware

Description

Global Group is a newly emerged Ransomware-as-a-Service operation believed to be a rebranding of the BlackLock/Mamona ecosystem. They offer innovative features like AI-powered negotiation systems and an affiliate revenue share model. The group is linked to Russian infrastructure and deploys sophisticated tactics to infiltrate targets.

Key insights

  • Employs AI-driven negotiation tools for ransom discussions.
  • Utilizes a double extortion model, leveraging both data encryption and data leaks.
  • Targets various sectors, including healthcare, education, and manufacturing.
  • Relies on Initial Access Brokers for pre-compromised entry points.
  • Uses Golang, C++, and C to build cross-platform ransomware.
  • Known for aggressive negotiation tactics, including threats of public data exposure.

Threat Level & Status Breakdown

For global · Based on incidents in selected period

3.1threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality4.4/ 10

Status Breakdown

Claimed13.3%4
First seenJun 2025
Last seenAug 2025
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for global in the selected period

30Total attacks
14peak in Jun
10avg / month
↓ 12 vs first month
JunJulAug0481216

Intelligence

IOCs, YARA/Sigma rules, and related families for global

  1. 16bc5adc4f46cdf7c4852d17ebf9f499
  2. 1f6640102f6472523830d69630def669dc3433bbb1c0e6183458bd792d420f8e
  3. 2a0ec79f3d0d2f2996a9c5263a112197
  4. c5f49c0f566a114b529138f8bd222865c9fa9fa95f96ec1ded50700764a1d4e7
  5. 8bf379efd813e2b19e3c0abf2dc08f05
  6. b4315d71fb374e4d6b12b7b3c412b027f2d5c231
  7. 55f3a2d89485bb40ea45e5fa1f24828f71a81ef4ccc541b6657fc7a861ef3add
  8. 70a4afab44d6a9ecd7f42ab77972be074dec8383a47a2011eb0133a230a4fae3
  9. 2e339540ab604bb0b317fab1e61c99e44c09ce32
  10. 74c021250ef2c027deb141d8f8b35329de082209
  11. 28f3de066878cb710fe5d44f7e11f65f25328beff953e00587ffeb5ac4b2faa8
View full IOC feed15 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for global

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1021

T1021

T1562

T1562

T1059

T1059

T1047

T1047

T1080

T1080

T1021.001

T1021.001

T1203

T1203

T1110

T1110

T1003

T1003

Victims(30)

CompanyDomainCountryIndustryStatusDiscovered
awmedicalvillage.orgawmedicalvillage.orgLB LebanonHealthcare
Unknown
10 months ago
hmsaojose.comhmsaojose.comBR BrazilHealthcare
Unknown
10 months ago
RUKU Tore - Türenrukutore.deDE GermanyManufacturing
Unknown
10 months ago
Albavision.tvalbavision.tvGT GuatemalaTechnology
Unknown
10 months ago
Medical Village LIVCH SwitzerlandHealthcare
Unknown
10 months ago
Rete Toscana Classicartcn.toscana.itIT ItalyTechnology
Unknown
10 months ago
Geomaticks Greciageomaticks.grGR GreeceProfessional Services
Unknown
10 months ago
Dithelm Travel Groupdthtravel.comTH ThailandHospitality
Unknown
10 months ago
Cyme Servicios Médicoscymserviciosmedicos.com.mxMX MexicoHealthcare
Unknown
10 months ago
MukundRhotindianNA Namibia
Unknown
10 months ago
CONTRAQIMX MexicoTechnology
Unknown
10 months ago
RTEIE IrelandTechnology
Unknown
10 months ago
moelco.esmoelco.esES SpainManufacturing
Unknown
10 months ago
lafavoritaservice.itlafavoritaservice.itIT ItalyManufacturing
Unknown
10 months ago
loraincountyauditor.govloraincountyauditor.govUS United StatesGovernment & Defense
Unknown
11 months ago
Emphail.comemphail.comUS United StatesTechnology
Unknown
11 months ago
entab.seentab.seSE SwedenTechnology
Unknown
11 months ago
Skyline Dubuqueskylinesalt.comUS United StatesOther
Unknown
12 months ago
Letryletry.beBE BelgiumOther
Unknown
12 months ago
Fenol Kimyafenol.com.trTR TurkeyManufacturing
Unknown
12 months ago

Page 1 of 2