<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Global Group - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/actors/global-group/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 20:01:41 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/actors/global-group/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Global Group Ransomware-as-a-Service Operations</title><link>https://feed.craftedsignal.io/briefs/2026-09-global-group-ransomware/</link><pubDate>Tue, 22 Sep 2026 20:01:41 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-global-group-ransomware/</guid><description>The Global Group, a RaaS operation evolved from Black Lock and Mamona, distributes ransomware via phishing-delivered ISO files and legitimate tool abuse to perform double-extortion attacks.</description><content:encoded><![CDATA[<p>The Global Group is a financially motivated Ransomware-as-a-Service (RaaS) operation that recently emerged as a rebranding of the legacy Black Lock and Mamona ransomware families. By inheriting established backend infrastructure and reusing core code artifacts, the group has quickly scaled its extortion activities. The group primarily targets large-scale enterprises across multiple industries, utilizing &quot;double extortion&quot; tactics where sensitive data is stolen and leaked publicly if ransom demands are not met. They coordinate closely with Initial Access Brokers (IABs) to facilitate network entry. Their delivery method relies on social engineering through phishing emails that pose as &quot;Suggested Payment Plans,&quot; leading victims to malicious download sites that serve ISO-based payloads. The operation uses legitimate Windows tools to masquerade malicious activity, effectively bypassing traditional perimeter defenses before deploying encryption toolkits in the C:\Python27.x86 directory.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Phishing: Attacker sends an email posing as a payment plan, containing a PDF document (&quot;document_989399.pdf&quot;).</li>
<li>Redirection: The PDF contains a button linking to a malicious site (hXXps://driverupdate[.]sbs/access[.]php) to prompt a file download.</li>
<li>Payload Delivery: The victim downloads a malicious ISO file (&quot;Preview-9dc7.iso&quot;) containing a shortcut and an executable.</li>
<li>Execution: The user runs the executable, which spawns a legitimate process, &quot;WinMerge.exe&quot;, to mask subsequent network activity.</li>
<li>C2 Communication: The compromised process connects to &quot;hXXps://globalsupportupdate[.]top&quot; to download the primary encryptor (&quot;enc.exe&quot;).</li>
<li>Persistence/Execution: The encryptor drops toolkit components into &quot;C:\Python27.x86&quot; and initiates a scan of local drivers and network shares.</li>
<li>Impact: The ransomware encrypts files using a proprietary cryptographic algorithm and appends the &quot;.nZASJgT&quot; extension.</li>
<li>Extortion: The malware changes the desktop wallpaper and drops a &quot;README.nZASJgT.txt&quot; ransom note, initiating business-style negotiations for data recovery and silence.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The Global Group ransomware poses a significant threat to global enterprise operations, resulting in the loss of data availability through encryption and the compromise of confidential corporate information via double extortion. By framing negotiations as professional business transactions, the group creates high-pressure environments for victim organizations. Successful attacks result in operational downtime, potential regulatory fines, and reputational damage due to the threat of public data exposure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the provided Sigma rule to detect the execution of &quot;WinMerge.exe&quot; when initiated from non-standard user profile paths or associated with suspicious network connections.</li>
<li>Monitor for the creation of files with the &quot;.nZASJgT&quot; extension on local disks and network shares as an early indicator of encryption activity.</li>
<li>Block the C2 infrastructure domains and URLs identified in the IOC section at the enterprise DNS resolver and proxy.</li>
<li>Audit for unauthorized file system modifications and directory creation within the &quot;C:\Python27.x86&quot; path.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>ransomware</category><category>phishing</category><category>double-extortion</category></item></channel></rss>