GlobeImposter ransomware was distributed through malicious JavaScript downloaders delivered by spam campaigns and, in some cases, the Necurs botnet, with lures posing as shared photos and compressed archives masquerading as image files. Researchers reported samples such as IMG_8798.js downloading payloads from remote infrastructure and launching them with process-hollowing-like behavior, then establishing persistence in public user directories and via RunOnce registry entries. The malware family is a copycat of Globe ransomware, reusing similar ransom-note and file-renaming behavior while evolving into multiple variants, including one that appended ..726 and another that appended ..doc to encrypted files.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
In February 2023, AhnLab described a ransomware campaign affecting South Korean organizations and named the malware 'TZW' ransomware. SentinelOne later assessed TZW as a rebranded GlobeImposter variant based on overlapping code, ransom-note structure, TOR portals, and shared server infrastructure.
On December 26, 2017, the Necurs botnet delivered the GlobeImposter ..doc variant through spam messages containing ZIP archives with JavaScript downloaders. Analysis linked the malware to C2 IPs 137.254.120.31 and 74.220.219.67 and Tor decryption service URLs.
A GlobeImposter sample later tied to the ..doc variant was first seen in the wild, according to VirusTotal. This variant would go on to append ..doc to encrypted files and use Read___ME.html ransom notes.
A December 2017 malspam campaign distributed a GlobeImposter variant via photo-themed emails carrying 7z archives with obfuscated JavaScript downloaders. The ransomware appended ..doc to encrypted files, dropped Read___ME.html, and directed victims to a Tor payment site.
FortiGuard Labs reported JavaScript downloaders spreading a new GlobeImposter variant identified as version 726. The malware downloaded its payload, established persistence, deleted shadow copies, killed processes, encrypted files with the ..726 extension, and dropped RECOVER-FILES-726.html ransom notes.
Emsisoft published a free decryption tool page for GlobeImposter, describing the ransomware as a Globe copycat that appends the .crypt extension and drops HOW_OPEN_FILES.hta ransom notes. The page also explained that decryption requires an encrypted file and its original unencrypted counterpart.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourceacronis.com
Open sourcebleepingcomputer.com
Open sourceblog.fortinet.com
Open sourceemsisoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.