Threats Tagged 'threat-actor'
View all threats tagged with 'threat-actor'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'threat-actor'
Click on any threat for detailed analysis and mitigation recommendations
Threat Actor Profile: The "Global" Ransomware Group 0 The "Global" ransomware group is a ransomware-as-a-service (RaaS) operation first publicly identified in June 2025. It appears to be a rebrand or continuation of the BlackLock ransomware group, sharing infrastructure and malware characteristics. The group operates a mature affiliate program with advanced features such as AI-assisted victim communications and offers up to 85% revenue share to affiliates. Their malware targets multiple platforms including Windows, Linux, ESXi, and NAS devices, using ChaCha20-Poly1305 encryption. They also deploy a custom stealer called WorldThief to facilitate double extortion. The group relies on purchased access through compromised credentials and exploited edge devices from vendors like Fortinet, Palo Alto, and Cisco. Their operations have been observed in over 18 countries. An operational security lapse exposed a backend IP linked to a Russian VPS provider, also associated with BlackLock. This case illustrates how ransomware groups recycle infrastructure and tooling across rebrands. Join the discussion | Reddit ThreatIntel | 07/30/2026, 07:24:11 UTC Added: 07/30/2026, 07:37:04 UTC |
Showing 1 to 1 of 1 result