Skip to main content

Threat Actor Profile: The "Global" Ransomware Group

0
Medium
Published: 07/30/2026 (07/30/2026, 07:24:11 UTC)
Source: Reddit ThreatIntel

Description

The "Global" ransomware group is a ransomware-as-a-service (RaaS) operation first publicly identified in June 2025. It appears to be a rebrand or continuation of the BlackLock ransomware group, sharing infrastructure and malware characteristics. The group operates a mature affiliate program with advanced features such as AI-assisted victim communications and offers up to 85% revenue share to affiliates. Their malware targets multiple platforms including Windows, Linux, ESXi, and NAS devices, using ChaCha20-Poly1305 encryption. They also deploy a custom stealer called WorldThief to facilitate double extortion. The group relies on purchased access through compromised credentials and exploited edge devices from vendors like Fortinet, Palo Alto, and Cisco. Their operations have been observed in over 18 countries. An operational security lapse exposed a backend IP linked to a Russian VPS provider, also associated with BlackLock. This case illustrates how ransomware groups recycle infrastructure and tooling across rebrands.

Reddit Discussion

r/threatintel·posted by u/Cyble_Vision
00

Been tracking a newer RaaS operation called Global (also styled "GLOBAL") that's worth knowing about if you're in threat intel or IR.

Quick background:

  • First surfaced publicly in June 2025, promoted on the RAMP underground forum by an actor going by "$$$"
  • Strong technical/infrastructure overlap with the old BlackLock operation (shared VPS provider, matching malware mutex values, overlapping leak-site infra) — also some links to Mamona RaaS
  • Looks less like a new group from scratch and more like a continuation/rebrand of prior ransomware activity

How it works:

  • RaaS model with a genuinely mature affiliate program — dedicated negotiation portal, mobile management, AI-assisted victim comms, up to 80–85% revenue share for affiliates
  • Malware is written in Go, uses ChaCha20-Poly1305 encryption, and hits Windows, Linux, ESXi, and NAS
  • They also ship a custom stealer called WorldThief (quiet mode, bandwidth throttling, targeted file collection, raw TCP exfil) to support double extortion

Access & targeting:

  • Relies heavily on purchased access — IABs, compromised VPN/OWA/RDWeb creds, and exploited edge devices (Fortinet, Palo Alto, Cisco)
  • Opportunistic across industries, activity seen in 18+ countries so far
  • Ironically, their own OPSEC slipped — a backend IP got exposed, tracing back to a Russian VPS provider (IpServer) also linked to BlackLock

Why it matters: it's a good example of how ransomware "brands" aren't really standalone — infra, tooling, and even affiliates get recycled across groups after takedowns or rebrands. If you've got old BlackLock IOCs sitting around, they may still have relevance here.

More information: https://cyble.com/threat-actor-profiles/global-ransomware-group/

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 07:37:29 UTC

Technical Analysis

The Global ransomware group is a ransomware-as-a-service operation that emerged in mid-2025, linked to the earlier BlackLock group through shared infrastructure and malware traits. It uses a sophisticated affiliate model with features such as a negotiation portal, mobile management, and AI-assisted victim communication. The malware is written in Go and employs ChaCha20-Poly1305 encryption, targeting Windows, Linux, ESXi, and NAS platforms. The group supports double extortion by deploying a custom stealer named WorldThief, which operates quietly and selectively exfiltrates data. Access is primarily gained via purchased credentials and exploitation of edge devices from major vendors. The group’s activity spans at least 18 countries. An exposed backend IP address revealed ties to a Russian VPS provider, highlighting a lapse in their operational security. This profile underscores the persistence and evolution of ransomware operations through rebranding and infrastructure reuse.

Potential Impact

The Global ransomware group conducts ransomware attacks across multiple operating systems and network-attached storage devices, encrypting victim data with strong encryption and employing double extortion tactics by stealing data with a custom stealer. Their mature affiliate program and advanced victim communication tools increase the efficiency and scale of their operations. The group’s reliance on purchased access and exploitation of widely used edge devices increases the attack surface and potential victim pool. Their activity affects organizations in over 18 countries, indicating a broad geographic impact. The reuse of infrastructure from previous ransomware groups suggests that existing indicators of compromise (IOCs) related to BlackLock may still be relevant for detection and defense.

Defensive Guidance

No official patch or remediation is applicable as this is a threat actor profile rather than a software vulnerability. Defenders should leverage existing IOCs related to BlackLock and monitor for indicators associated with the Global group. Organizations should ensure strong credential hygiene, patch and secure edge devices (Fortinet, Palo Alto, Cisco), and monitor for signs of purchased access or unusual authentication activity. Incident response teams should be aware of the group’s use of double extortion and the WorldThief stealer. Since no vendor advisory or patch is available, follow vendor guidance for securing affected infrastructure and apply best practices for ransomware defense relevant to the exploited vectors.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
ThreatIntelligence+threatintel+websecurityresearch
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":33,"reasons":["external_link","newsworthy_keywords:ransomware,threat actor","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["ransomware","threat actor"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a6aff209c2644c7f8bc0464

Added to database: 07/30/2026, 07:37:04 UTC

Last enriched: 07/30/2026, 07:37:29 UTC

Last updated: 09/10/2026, 20:33:37 UTC

Views: 137

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses