Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

Global Group Ransomware Group

Ransomware group profile

4Victims
RussiaSource country
83Impact score
Also Known As
global ransomware

Description

Global Group is a newly emerged Ransomware-as-a-Service operation believed to be a rebranding of the BlackLock/Mamona ecosystem. They offer innovative features like AI-powered negotiation systems and an affiliate revenue share model. The group is linked to Russian infrastructure and deploys sophisticated tactics to infiltrate targets.

Key insights

  • •Employs AI-driven negotiation tools for ransom discussions.
  • •Utilizes a double extortion model, leveraging both data encryption and data leaks.
  • •Targets various sectors, including healthcare, education, and manufacturing.
  • •Relies on Initial Access Brokers for pre-compromised entry points.
  • •Uses Golang, C++, and C to build cross-platform ransomware.
  • •Known for aggressive negotiation tactics, including threats of public data exposure.

Threat Level & Status Breakdown

For Global Group · Based on incidents in selected period

1.6threat level
Aggressiveness1/ 10
Lethality0/ 10
Criticality4.2/ 10

Status Breakdown

Claimed100.0%4
First seenAug 2026
Last seenAug 2026
Avg ransom—
Payment rate—
Statusactive
Sophistication0
Last updatedOct 8, 2026

Recent activity

Monthly attack count for Global Group in the selected period

4Total attacks
4peak in Aug
4avg / month
Aug01234

Intelligence

IOCs, YARA/Sigma rules, and related families for Global Group

  1. c5f49c0f566a114b529138f8bd222865c9fa9fa95f96ec1ded50700764a1d4e7
  2. 2a0ec79f3d0d2f2996a9c5263a112197
  3. b4315d71fb374e4d6b12b7b3c412b027f2d5c231
  4. 1f6640102f6472523830d69630def669dc3433bbb1c0e6183458bd792d420f8e
  5. 4e01e0eca4d82cbadc70b754a4f9fd3c
  6. a8c28bd6f0f1fe6a9b880400853fc86e46d87b69565ef15d8ab757979cd2cc73
  7. dffec40e5723d9551c848cde5786d379fd734b8e
  8. 13b82f4ac62faf87a105be355c82bacfcbdd383050860dfa93dfbb7bb2e6c9ba
  9. c95056c8682373d0512aea2ed72c18f79c854308
  10. c5a8d4c07e1dca5e9cfbbaadfc402063
  11. ca979fad68362cd3d9ad24424d5ac3fd
  12. c7b91de4b4b10c22f2e3bca1e2603160588fd8fd829fd46103cf536b6082e310
  13. 0fc658c1c4f3570122f29465b3e0bfa0
  14. 16bc5adc4f46cdf7c4852d17ebf9f499
  15. 2e339540ab604bb0b317fab1e61c99e44c09ce32
  16. 28f3de066878cb710fe5d44f7e11f65f25328beff953e00587ffeb5ac4b2faa8
  17. 232f86e26ced211630957baffcd36dd3bcd6a786f3d307127e1ea9a8b31c199f
  18. 16f43a742a66734fea50d53a2dfdcdbe2e3afc00
  19. b5e811d7c104ce8dd2509f809a80932540a21ada0ee9e22ac61d080dc0bd237d
  20. 70a4afab44d6a9ecd7f42ab77972be074dec8383a47a2011eb0133a230a4fae3
  21. 8bf379efd813e2b19e3c0abf2dc08f05
  22. 74c021250ef2c027deb141d8f8b35329de082209
  23. 55f3a2d89485bb40ea45e5fa1f24828f71a81ef4ccc541b6657fc7a861ef3add
  24. 9fb468a79f88d9a250180749bfae97d4f310c8510f1f98cae359d95c2a62b4af
  25. 20417846820741fa84c4571affb40e9c
  26. 64388cdbfe48dcff05eaa455892bcb3bfcaa3d43559eb7c65f6ac772810be61e
  27. 1e2c4cd35987ee217994149675784f9f
  28. 997cf28771fde81c6bfc067eed1f19d0ad3554342d63d9469d3adcdc1ca0ff31
  29. 5dee17e91f79be742881324bcdf139a5
  30. 00f70ae018e71f51060346aaa101209c24e34697bbfafec6b3612db8d8127cb2
  31. 9db4b94589728b68d51bf83a90211cfe
  32. d5004e079cb46db15a7d0b7ecebfa47bb8a1bc19e25749849a017b2a36705260
  33. 2abd445d3d60fd207b2c62bb0da3a42b
View full IOC feed52 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for Global Group

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1021

T1021

T1562

T1562

T1059

T1059

T1047

T1047

T1080

T1080

T1021.001

T1021.001

T1203

T1203

T1110

T1110

T1003

T1003

Victims(4)

ChinaTechnologyatcomm.cn
Claimed
about 1 month ago
SingaporeTransportationstecs.com.sg
Claimed
about 1 month ago
ChinaHealthcareqihanbio.com
Claimed
about 1 month ago
UruguayTechnologyvigilia.com.uy
Claimed
about 1 month ago