Uptime Hamster: 10d 6h 2mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Global Group

Global Group

0 incidentes 0 paises 0 sectores ransomware RU Ultimo: -
Aliases: global ransomware
Ver en IntelTracker → APTTrail →
Global Group is a ransomware-as-a-service operation that emerged on June 2, 2025, promoted by a Russian-speaking threat actor known as "$$$" on the Ramp4u cybercrime forum. The group is assessed with medium confidence to be a rebranding of the BlackLock RaaS, which itself evolved from Eldorado, and shares ties with the Mamona ransomware family. Global Group's primary motivation is financial, offering affiliates a high percentage, typically 80% to 85%, of ransom proceeds. This group distinguishes itself through its integration of AI-powered negotiation chatbots and a mobile-friendly affiliate control panel, alongside customizable cross-platform payload builders, making it a competitive and rapidly expanding entity in the ransomware landscape. It reuses the mutex key Global\Fxo16jmdgujs437, indicating a direct lineage from Mamona ransomware.

Aliases del actor

global ransomware

Actores similares

fletchenransomware · 2BravoX Ransomwareransomware · 0Cloak Ransomwareransomware · 0Cicada3301ransomware · 0Proton Ransomwareransomware · 0Limba Ransomwareransomware · 0Amelia Ransomwareransomware · 0Synapse Ransomwareransomware · 0Trinity Ransomwareransomware · 0Orion Ransomwareransomware · 0
Tecnicas MITRE
T1071.001-, T1486-, T1568-, T1190-, T1133-, T1598-
Tipo
ransomware
Pais origen
RU
Motivacion
-
Impacto
80
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustraliaArubaBelgiumBrazilCanadaCongo, the Democratic Republic of theCongoGermany

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesSoftware PublishersHospitalsEnterprises & HoldingAccommodationManufacturingConstructionPublic AdministrationAdministrative &Waste Management