Global Group is a financially motivated ransomware-as-a-service (RaaS) operation targeting large, high-value organizations across multiple sectors. It is widely tracked as a rebrand and operational continuation of BlackLock (also styled Black Lock), which was previously known as Eldorado or El Dorado; Mamona has also been identified as a historical ransomware family connected to the operation. Global Group operates an affiliate model and has reportedly obtained access to compromised corporate environments through initial-access brokers. The group has used phishing lures to deliver ransomware through multi-stage download chains and abuse of legitimate software. Its encryptor targets local storage, network shares, and databases, and can disable security processes before encrypting victim data. Global Group conducts double-extortion operations, combining encryption with theft of sensitive data and threats of public disclosure through its leak infrastructure. Its extortion messaging offers decryption, recovery guidance, and assistance framed around insurance and reputation management. Global Group has deployed an AI-assisted negotiation chatbot through its victim communication portal. The chatbot is used to manage victim intake, tailor negotiation messaging, and apply continuous psychological pressure, enabling affiliates and operators to scale extortion activity across time zones. Reported victim activity has disproportionately affected health care, construction, and manufacturing organizations, while the operation has also been associated with attacks against U.S. organizations in government and other sectors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
40 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-Service operation targeting large enterprises through phishing-delivered ransomware. It uses double extortion, encrypting victim files while stealing data and threatening publication, and also works with initial-access brokers to obtain access to compromised corporate networks.
Financially motivated ransomware-as-a-service operation, described as a rebrand of Black Lock and Mamona, reusing their backend infrastructure and code artifacts to support scalable extortion against large, high-value enterprises across industries.
Financially motivated RaaS operation targeting high-value, large-scale enterprises. The group is described as a rebranding built on legacy Black Lock and Mamona ransomware infrastructure and code artifacts. It uses initial-access brokers to acquire pre-compromised corporate credentials and conducts double-extortion ransomware operations.
Uses an independently verified AI negotiation chatbot for continuous victim intake and psychological pressure during ransomware extortion negotiations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.