Global Group is a Windows ransomware operation operated as ransomware-as-a-service (RaaS) and widely characterized as a successor or rebranding of the Mamona and Black Lock ransomware families. It has been delivered in phishing campaigns associated with the Phorpiex botnet, in which deceptive ZIP or shortcut attachments use double extensions to masquerade as documents. Executing the shortcut invokes built-in Windows command-line utilities and PowerShell to retrieve and launch the ransomware.
Global Group encrypts files on local drives, network shares, and databases, and has been reported to use ChaCha20-Poly1305 encryption. A notable feature is its offline “mute” mode: encryption keys are generated locally, allowing the ransomware to operate without command-and-control communications, including against isolated or air-gapped systems. The malware impairs recovery by deleting Volume Shadow Copies, terminates database and analysis-related processes to maximize file access, and uses delayed self-deletion to reduce forensic evidence. It changes the victim desktop wallpaper and provides payment and recovery instructions through a ransom note. The operation has targeted enterprise victims and uses a Tor-based negotiation portal that includes an AI chatbot intended to automate victim communications and apply pressure during ransom negotiations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation delivered through phishing emails. Its encryptor is retrieved through an abuse of the legitimate WinMerge application, disables security processes, encrypts local drives, network shares, and databases, appends the nZASJgT extension, and deploys ransom notes. The operators also use double extortion.
Ransomware delivered via phishing (ZIP + double-extension LNK) that can run offline, generates local ChaCha20-Poly1305 keys, deletes shadow copies, self-deletes, and kills analysis/database-related processes.
RaaS operation active since early June 2025 targeting multiple regions/sectors; uses AI-driven negotiation tooling (per summary).
Ransomware strain delivered via malspam campaigns attributed to Phorpiex botnet activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.