Global Group
0 incidentes
0 paises
0 sectores
ransomware RU Ultimo: -
Aliases: global ransomware
Global Group is a ransomware-as-a-service operation that emerged on June 2, 2025, promoted by a Russian-speaking threat actor known as "$$$" on the Ramp4u cybercrime forum. The group is assessed with medium confidence to be a rebranding of the BlackLock RaaS, which itself evolved from Eldorado, and shares ties with the Mamona ransomware family. Global Group's primary motivation is financial, offering affiliates a high percentage, typically 80% to 85%, of ransom proceeds. This group distinguishes itself through its integration of AI-powered negotiation chatbots and a mobile-friendly affiliate control panel, alongside customizable cross-platform payload builders, making it a competitive and rapidly expanding entity in the ransomware landscape. It reuses the mutex key Global\Fxo16jmdgujs437, indicating a direct lineage from Mamona ransomware.
Paises objetivo (SOCRadar)
United Arab Emirates
Argentina
AustraliaAruba
Belgium
Brazil
CanadaCongo, the Democratic Republic of theCongo
Germany
Sectores objetivo (SOCRadar)
Construction of BuildingsOther Information ServicesSoftware PublishersHospitalsEnterprises & HoldingAccommodationManufacturingConstructionPublic AdministrationAdministrative &Waste Management