{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/global-group/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Global Group"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["ransomware","phishing","double-extortion"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eThe Global Group is a financially motivated Ransomware-as-a-Service (RaaS) operation that recently emerged as a rebranding of the legacy Black Lock and Mamona ransomware families. By inheriting established backend infrastructure and reusing core code artifacts, the group has quickly scaled its extortion activities. The group primarily targets large-scale enterprises across multiple industries, utilizing \u0026quot;double extortion\u0026quot; tactics where sensitive data is stolen and leaked publicly if ransom demands are not met. They coordinate closely with Initial Access Brokers (IABs) to facilitate network entry. Their delivery method relies on social engineering through phishing emails that pose as \u0026quot;Suggested Payment Plans,\u0026quot; leading victims to malicious download sites that serve ISO-based payloads. The operation uses legitimate Windows tools to masquerade malicious activity, effectively bypassing traditional perimeter defenses before deploying encryption toolkits in the C:\\Python27.x86 directory.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePhishing: Attacker sends an email posing as a payment plan, containing a PDF document (\u0026quot;document_989399.pdf\u0026quot;).\u003c/li\u003e\n\u003cli\u003eRedirection: The PDF contains a button linking to a malicious site (hXXps://driverupdate[.]sbs/access[.]php) to prompt a file download.\u003c/li\u003e\n\u003cli\u003ePayload Delivery: The victim downloads a malicious ISO file (\u0026quot;Preview-9dc7.iso\u0026quot;) containing a shortcut and an executable.\u003c/li\u003e\n\u003cli\u003eExecution: The user runs the executable, which spawns a legitimate process, \u0026quot;WinMerge.exe\u0026quot;, to mask subsequent network activity.\u003c/li\u003e\n\u003cli\u003eC2 Communication: The compromised process connects to \u0026quot;hXXps://globalsupportupdate[.]top\u0026quot; to download the primary encryptor (\u0026quot;enc.exe\u0026quot;).\u003c/li\u003e\n\u003cli\u003ePersistence/Execution: The encryptor drops toolkit components into \u0026quot;C:\\Python27.x86\u0026quot; and initiates a scan of local drivers and network shares.\u003c/li\u003e\n\u003cli\u003eImpact: The ransomware encrypts files using a proprietary cryptographic algorithm and appends the \u0026quot;.nZASJgT\u0026quot; extension.\u003c/li\u003e\n\u003cli\u003eExtortion: The malware changes the desktop wallpaper and drops a \u0026quot;README.nZASJgT.txt\u0026quot; ransom note, initiating business-style negotiations for data recovery and silence.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe Global Group ransomware poses a significant threat to global enterprise operations, resulting in the loss of data availability through encryption and the compromise of confidential corporate information via double extortion. By framing negotiations as professional business transactions, the group creates high-pressure environments for victim organizations. Successful attacks result in operational downtime, potential regulatory fines, and reputational damage due to the threat of public data exposure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect the execution of \u0026quot;WinMerge.exe\u0026quot; when initiated from non-standard user profile paths or associated with suspicious network connections.\u003c/li\u003e\n\u003cli\u003eMonitor for the creation of files with the \u0026quot;.nZASJgT\u0026quot; extension on local disks and network shares as an early indicator of encryption activity.\u003c/li\u003e\n\u003cli\u003eBlock the C2 infrastructure domains and URLs identified in the IOC section at the enterprise DNS resolver and proxy.\u003c/li\u003e\n\u003cli\u003eAudit for unauthorized file system modifications and directory creation within the \u0026quot;C:\\Python27.x86\u0026quot; path.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T20:01:41Z","date_published":"2026-09-22T20:01:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-global-group-ransomware/","summary":"The Global Group, a RaaS operation evolved from Black Lock and Mamona, distributes ransomware via phishing-delivered ISO files and legitimate tool abuse to perform double-extortion attacks.","title":"Global Group Ransomware-as-a-Service Operations","url":"https://feed.craftedsignal.io/briefs/2026-09-global-group-ransomware/"}],"language":"en","title":"CraftedSignal Threat Feed - Global Group","version":"https://jsonfeed.org/version/1.1"}