Forcepoint X-Labs reported a high-volume phishing campaign leveraging the long-running Phorpiex botnet to deliver Global Group ransomware (described as a successor to the Mamona family). The emails commonly use the subject line “Your Document” and include attachments that appear to be documents inside ZIP archives but are actually malicious Windows Shortcut files (.lnk) disguised via double extensions such as Document.doc.lnk—a tactic that benefits from Windows hiding file extensions by default. When opened, the shortcut triggers a living-off-the-land execution chain (e.g., cmd.exe and PowerShell) to download and run a secondary payload that may be named to resemble a legitimate component (e.g., windrv.exe).
Reporting highlighted that Global Group ransomware can operate in a “mute” mode, enabling offline encryption behavior intended to reduce reliance on command-and-control and evade some traditional detections. Separate coverage about the purported 0APT leak site and a Coveware/Clop-focused analysis of downstream mass data-extortion payment trends are not part of this Phorpiex/Global Group activity and do not add incident-specific details to the LNK-based ransomware delivery campaign.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Forcepoint X-Labs publicly reported the phishing campaign and detailed how malicious LNK files, living-off-the-land execution, and Phorpiex malware were being used to deliver Global Group ransomware. The report also highlighted the ransomware's offline capability and anti-forensic behavior.
Researchers observed Global Group ransomware, described as a successor to Mamona, operating in a mode that generates encryption keys locally and does not require command-and-control communication. The malware could therefore encrypt offline or air-gapped systems while also deleting shadow copies, self-deleting, and appending the .Reco extension to files.
A phishing campaign active throughout 2024 and 2025 used emails such as "Your Document" with deceptive .lnk attachments like "Document.doc.lnk" to infect victims. The shortcuts abused cmd.exe and PowerShell to download Phorpiex-related payloads that ultimately deployed Global Group ransomware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcehackread.com
Open sourceforcepoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.