Threat Actor Profile: The "Global" Ransomware Group
The "Global" ransomware group is a ransomware-as-a-service (RaaS) operation first publicly identified in June 2025. It appears to be a rebrand or continuation of the BlackLock ransomware group, sharing infrastructure and malware characteristics. The group operates a mature affiliate program with advanced features such as AI-assisted victim communications and offers up to 85% revenue share to affiliates. Their malware targets multiple platforms including Windows, Linux, ESXi, and NAS devices, using ChaCha20-Poly1305 encryption. They also deploy a custom stealer called WorldThief to facilitate double extortion. The group relies on purchased access through compromised credentials and exploited edge devices from vendors like Fortinet, Palo Alto, and Cisco. Their operations have been observed in over 18 countries. An operational security lapse exposed a backend IP linked to a Russian VPS provider, also associated with BlackLock. This case illustrates how ransomware groups recycle infrastructure and tooling across rebrands.
AI Analysis
Technical Summary
The Global ransomware group is a ransomware-as-a-service operation that emerged in mid-2025, linked to the earlier BlackLock group through shared infrastructure and malware traits. It uses a sophisticated affiliate model with features such as a negotiation portal, mobile management, and AI-assisted victim communication. The malware is written in Go and employs ChaCha20-Poly1305 encryption, targeting Windows, Linux, ESXi, and NAS platforms. The group supports double extortion by deploying a custom stealer named WorldThief, which operates quietly and selectively exfiltrates data. Access is primarily gained via purchased credentials and exploitation of edge devices from major vendors. The group’s activity spans at least 18 countries. An exposed backend IP address revealed ties to a Russian VPS provider, highlighting a lapse in their operational security. This profile underscores the persistence and evolution of ransomware operations through rebranding and infrastructure reuse.
Potential Impact
The Global ransomware group conducts ransomware attacks across multiple operating systems and network-attached storage devices, encrypting victim data with strong encryption and employing double extortion tactics by stealing data with a custom stealer. Their mature affiliate program and advanced victim communication tools increase the efficiency and scale of their operations. The group’s reliance on purchased access and exploitation of widely used edge devices increases the attack surface and potential victim pool. Their activity affects organizations in over 18 countries, indicating a broad geographic impact. The reuse of infrastructure from previous ransomware groups suggests that existing indicators of compromise (IOCs) related to BlackLock may still be relevant for detection and defense.
Mitigation Recommendations
No official patch or remediation is applicable as this is a threat actor profile rather than a software vulnerability. Defenders should leverage existing IOCs related to BlackLock and monitor for indicators associated with the Global group. Organizations should ensure strong credential hygiene, patch and secure edge devices (Fortinet, Palo Alto, Cisco), and monitor for signs of purchased access or unusual authentication activity. Incident response teams should be aware of the group’s use of double extortion and the WorldThief stealer. Since no vendor advisory or patch is available, follow vendor guidance for securing affected infrastructure and apply best practices for ransomware defense relevant to the exploited vectors.
Threat Actor Profile: The "Global" Ransomware Group
Description
The "Global" ransomware group is a ransomware-as-a-service (RaaS) operation first publicly identified in June 2025. It appears to be a rebrand or continuation of the BlackLock ransomware group, sharing infrastructure and malware characteristics. The group operates a mature affiliate program with advanced features such as AI-assisted victim communications and offers up to 85% revenue share to affiliates. Their malware targets multiple platforms including Windows, Linux, ESXi, and NAS devices, using ChaCha20-Poly1305 encryption. They also deploy a custom stealer called WorldThief to facilitate double extortion. The group relies on purchased access through compromised credentials and exploited edge devices from vendors like Fortinet, Palo Alto, and Cisco. Their operations have been observed in over 18 countries. An operational security lapse exposed a backend IP linked to a Russian VPS provider, also associated with BlackLock. This case illustrates how ransomware groups recycle infrastructure and tooling across rebrands.
Reddit Discussion
Been tracking a newer RaaS operation called Global (also styled "GLOBAL") that's worth knowing about if you're in threat intel or IR.
Quick background:
- First surfaced publicly in June 2025, promoted on the RAMP underground forum by an actor going by "$$$"
- Strong technical/infrastructure overlap with the old BlackLock operation (shared VPS provider, matching malware mutex values, overlapping leak-site infra) — also some links to Mamona RaaS
- Looks less like a new group from scratch and more like a continuation/rebrand of prior ransomware activity
How it works:
- RaaS model with a genuinely mature affiliate program — dedicated negotiation portal, mobile management, AI-assisted victim comms, up to 80–85% revenue share for affiliates
- Malware is written in Go, uses ChaCha20-Poly1305 encryption, and hits Windows, Linux, ESXi, and NAS
- They also ship a custom stealer called WorldThief (quiet mode, bandwidth throttling, targeted file collection, raw TCP exfil) to support double extortion
Access & targeting:
- Relies heavily on purchased access — IABs, compromised VPN/OWA/RDWeb creds, and exploited edge devices (Fortinet, Palo Alto, Cisco)
- Opportunistic across industries, activity seen in 18+ countries so far
- Ironically, their own OPSEC slipped — a backend IP got exposed, tracing back to a Russian VPS provider (IpServer) also linked to BlackLock
Why it matters: it's a good example of how ransomware "brands" aren't really standalone — infra, tooling, and even affiliates get recycled across groups after takedowns or rebrands. If you've got old BlackLock IOCs sitting around, they may still have relevance here.
More information: https://cyble.com/threat-actor-profiles/global-ransomware-group/
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Global ransomware group is a ransomware-as-a-service operation that emerged in mid-2025, linked to the earlier BlackLock group through shared infrastructure and malware traits. It uses a sophisticated affiliate model with features such as a negotiation portal, mobile management, and AI-assisted victim communication. The malware is written in Go and employs ChaCha20-Poly1305 encryption, targeting Windows, Linux, ESXi, and NAS platforms. The group supports double extortion by deploying a custom stealer named WorldThief, which operates quietly and selectively exfiltrates data. Access is primarily gained via purchased credentials and exploitation of edge devices from major vendors. The group’s activity spans at least 18 countries. An exposed backend IP address revealed ties to a Russian VPS provider, highlighting a lapse in their operational security. This profile underscores the persistence and evolution of ransomware operations through rebranding and infrastructure reuse.
Potential Impact
The Global ransomware group conducts ransomware attacks across multiple operating systems and network-attached storage devices, encrypting victim data with strong encryption and employing double extortion tactics by stealing data with a custom stealer. Their mature affiliate program and advanced victim communication tools increase the efficiency and scale of their operations. The group’s reliance on purchased access and exploitation of widely used edge devices increases the attack surface and potential victim pool. Their activity affects organizations in over 18 countries, indicating a broad geographic impact. The reuse of infrastructure from previous ransomware groups suggests that existing indicators of compromise (IOCs) related to BlackLock may still be relevant for detection and defense.
Defensive Guidance
No official patch or remediation is applicable as this is a threat actor profile rather than a software vulnerability. Defenders should leverage existing IOCs related to BlackLock and monitor for indicators associated with the Global group. Organizations should ensure strong credential hygiene, patch and secure edge devices (Fortinet, Palo Alto, Cisco), and monitor for signs of purchased access or unusual authentication activity. Incident response teams should be aware of the group’s use of double extortion and the WorldThief stealer. Since no vendor advisory or patch is available, follow vendor guidance for securing affected infrastructure and apply best practices for ransomware defense relevant to the exploited vectors.
Technical Details
- Source Type
- Subreddit
- ThreatIntelligence+threatintel+websecurityresearch
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":33,"reasons":["external_link","newsworthy_keywords:ransomware,threat actor","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["ransomware","threat actor"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a6aff209c2644c7f8bc0464
Added to database: 07/30/2026, 07:37:04 UTC
Last enriched: 07/30/2026, 07:37:29 UTC
Last updated: 09/10/2026, 20:33:37 UTC
Views: 137
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.