Ransomware needs a way in. Stolen credentials are the cheapest one.
Global Group Ransomware Group
Ransomware group profile
Description
Global Group is a newly emerged Ransomware-as-a-Service operation believed to be a rebranding of the BlackLock/Mamona ecosystem. They offer innovative features like AI-powered negotiation systems and an affiliate revenue share model. The group is linked to Russian infrastructure and deploys sophisticated tactics to infiltrate targets.
Key insights
- •Employs AI-driven negotiation tools for ransom discussions.
- •Utilizes a double extortion model, leveraging both data encryption and data leaks.
- •Targets various sectors, including healthcare, education, and manufacturing.
- •Relies on Initial Access Brokers for pre-compromised entry points.
- •Uses Golang, C++, and C to build cross-platform ransomware.
- •Known for aggressive negotiation tactics, including threats of public data exposure.
Threat Level & Status Breakdown
For Global Group · Based on incidents in selected period
Recent activity
Monthly attack count for Global Group in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for Global Group
- c5f49c0f566a114b529138f8bd222865c9fa9fa95f96ec1ded50700764a1d4e7
- 2a0ec79f3d0d2f2996a9c5263a112197
- b4315d71fb374e4d6b12b7b3c412b027f2d5c231
- 1f6640102f6472523830d69630def669dc3433bbb1c0e6183458bd792d420f8e
- 4e01e0eca4d82cbadc70b754a4f9fd3c
- a8c28bd6f0f1fe6a9b880400853fc86e46d87b69565ef15d8ab757979cd2cc73
- dffec40e5723d9551c848cde5786d379fd734b8e
- 13b82f4ac62faf87a105be355c82bacfcbdd383050860dfa93dfbb7bb2e6c9ba
- c95056c8682373d0512aea2ed72c18f79c854308
- c5a8d4c07e1dca5e9cfbbaadfc402063
- ca979fad68362cd3d9ad24424d5ac3fd
- c7b91de4b4b10c22f2e3bca1e2603160588fd8fd829fd46103cf536b6082e310
- 0fc658c1c4f3570122f29465b3e0bfa0
- 16bc5adc4f46cdf7c4852d17ebf9f499
- 2e339540ab604bb0b317fab1e61c99e44c09ce32
- 28f3de066878cb710fe5d44f7e11f65f25328beff953e00587ffeb5ac4b2faa8
- 232f86e26ced211630957baffcd36dd3bcd6a786f3d307127e1ea9a8b31c199f
- 16f43a742a66734fea50d53a2dfdcdbe2e3afc00
- b5e811d7c104ce8dd2509f809a80932540a21ada0ee9e22ac61d080dc0bd237d
- 70a4afab44d6a9ecd7f42ab77972be074dec8383a47a2011eb0133a230a4fae3
- 8bf379efd813e2b19e3c0abf2dc08f05
- 74c021250ef2c027deb141d8f8b35329de082209
- 55f3a2d89485bb40ea45e5fa1f24828f71a81ef4ccc541b6657fc7a861ef3add
- 9fb468a79f88d9a250180749bfae97d4f310c8510f1f98cae359d95c2a62b4af
- 20417846820741fa84c4571affb40e9c
- 64388cdbfe48dcff05eaa455892bcb3bfcaa3d43559eb7c65f6ac772810be61e
- 1e2c4cd35987ee217994149675784f9f
- 997cf28771fde81c6bfc067eed1f19d0ad3554342d63d9469d3adcdc1ca0ff31
- 5dee17e91f79be742881324bcdf139a5
- 00f70ae018e71f51060346aaa101209c24e34697bbfafec6b3612db8d8127cb2
- 9db4b94589728b68d51bf83a90211cfe
- d5004e079cb46db15a7d0b7ecebfa47bb8a1bc19e25749849a017b2a36705260
- 2abd445d3d60fd207b2c62bb0da3a42b
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for Global Group
T1486
T1486
T1490
T1490
T1078
T1078
T1021
T1021
T1562
T1562
T1059
T1059
T1047
T1047
T1080
T1080
T1021.001
T1021.001
T1203
T1203
T1110
T1110
T1003
T1003
Victims(4)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| Atcomm | China | Claimed | about 1 month ago | |
| Shanghai Tunnel Engineering Co (Singapore) Pte Ltd | Singapore | Claimed | about 1 month ago | |
| QIHAN BIOTECH | China | Claimed | about 1 month ago | |
| Vigilia | Uruguay | Claimed | about 1 month ago |
Affected countries(33)
Countries where this group has been reported to target or leak victims.