Global, also referred to as GLOBAL GROUP, is a ransomware-as-a-service operation that emerged in June 2025. The group is notable for cross-platform ransomware capabilities spanning Windows, Linux, ESXi, NAS, and BSD-based systems, and for combining data theft with encryption to pressure victims. Reporting links Global to the earlier Mamona and BlackLock ransomware families through shared operational artifacts and overlapping operator activity, including use of the same forum persona associated with advertising and affiliate recruitment. Global operates a RaaS model in which affiliates conduct intrusions while the core operators provide lockers, management infrastructure, negotiation support, and decryptor delivery. The operation has advertised multilingual support and an affiliate revenue-sharing model. Its victimology has shown a strong concentration in healthcare and manufacturing, with additional publicly claimed victims in media and broadcasting. Observed intrusion tradecraft includes reliance on initial access brokers, phishing-delivered malware in some cases, password-spraying and brute-force activity against remote access services, and post-compromise use of credential abuse and token impersonation. Global supports LDAP-based propagation in Active Directory environments and has demonstrated lateral movement, privilege escalation, reconnaissance, defense evasion, and persistence behaviors typical of mature affiliate-driven ransomware intrusions. Pre-encryption activity has included data exfiltration, termination of security tools, deletion of shadow copies, and clearing of event logs. The ransomware uses modern encryption and multithreaded execution to accelerate impact across multiple drives and directories. It has also been reported to print ransom notes, alter desktop wallpapers, and use a negotiation portal with AI-assisted chat features to streamline extortion. Global’s extortion model is consistent with double extortion: affiliates steal data before encryption and threaten public release if victims do not pay within short deadlines. Demands have reached multimillion-dollar levels, and negotiations reportedly often begin aggressively before substantial concessions. Global is assessed as financially motivated. Its targeting pattern and operational design indicate a focus on organizations where downtime and data sensitivity increase leverage, particularly in healthcare and manufacturing environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A now-defunct ransomware group reportedly associated with an AI chatbot used to automate ransom negotiations.
Cross-platform ransomware operation introduced as “GLOBAL GROUP”; reporting ties it to earlier brands Mamona/BlackLock; opportunistic targeting with focus on high-impact virtualization/hypervisor environments.
Opportunistic ransomware operation emphasizing cross-platform encryption (Windows/Linux/ESXi), targeting high-impact enterprise infrastructure such as hypervisors/virtualized environments; reporting notes ties to earlier brands Mamona/BlackLock.
Financially motivated RaaS operation focused on extortion, with affiliates targeting healthcare and manufacturing organizations using cross-platform ransomware, pre-encryption data theft, aggressive negotiations, and AI-assisted Tor portal communications.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.