Global Group RaaS Unveils AI-Powered Negotiation Tools to Enhance Operations

Published:

spot_img

Emerging Threat: Understanding GLOBAL GROUP Ransomware

Cybersecurity experts have recently uncovered a new ransomware-as-a-service (RaaS) operation named GLOBAL GROUP. This organization has rapidly gained notoriety since its emergence in June 2025, with attacks reported across various sectors in Australia, Brazil, Europe, and the United States.

The Rise of GLOBAL GROUP

Prominently showcased on the Ramp4u forum by a threat actor known as $$$, GLOBAL GROUP seems to be a rebranding of the previously operational BlackLock RaaS. Earlier this year, a data leak site associated with BlackLock was defaced by the DragonForce ransomware cartel, leading to speculation that GLOBAL GROUP represents a new phase in this ongoing cybercriminal saga. It is noteworthy that BlackLock itself was a rebranding of an earlier scheme called Eldorado.

Tactics Employed by GLOBAL GROUP

The financial motivations driving GLOBAL GROUP influence its operational strategies. The group relies heavily on initial access brokers (IABs) to deploy its ransomware. By taking advantage of vulnerable edge appliances from well-known vendors such as Cisco, Fortinet, and Palo Alto Networks, they effectively target organizational weak points. Additionally, the use of brute-force utilities to access Microsoft Outlook and RDWeb portals adds another layer to their deployment methods.

Exploiting Corporate Vulnerabilities

$$$ has successfully secured Remote Desktop Protocol (RDP) or web shell access to several corporate networks, including those of law firms. This access enables them to deploy post-exploitation tools, conduct lateral movements within networks, siphon sensitive data, and ultimately unleash ransomware payloads.

By outsourcing the infiltration phase to other cybercriminals, GLOBAL GROUP allows its affiliates to focus on the more complex tasks of delivering ransomware, negotiating with victims, and extorting funds, rather than the intricate process of penetrating corporate defenses.

RaaS Features and Revenue Model

The GLOBAL GROUP RaaS platform includes a negotiation portal accompanied by an affiliate management panel. These tools are designed to assist cybercriminals in managing their victims, crafting ransomware payloads for various platforms—such as VMware ESXi, NAS, BSD, and Windows—and monitoring the overall operational progress. To attract more affiliates, GLOBAL GROUP offers a lucrative revenue-sharing model, reportedly providing up to 85% returns.

The negotiation panel also incorporates an AI-driven chatbot system, enabling effective communication with victims regardless of their language, thereby broadening the pool of potential affiliates.

Victim Profile and Industry Impact

As of mid-July 2025, GLOBAL GROUP has claimed 17 victims across various sectors, including healthcare, oil and gas, industrial machinery, automotive repair, and business process outsourcing. This diverse target list illustrates the broad scope of their operational ambitions.

The association with previously known RaaS entities such as BlackLock and Mamona further enriches the narrative surrounding GLOBAL GROUP. Evidence points to them sharing the same Russian VPS provider, IpServer, and similarities in source code with Mamona Ransomware. This evolution marks a strategic pivot aimed at enhancing operational reach, monetization potential, and competitiveness within the ransomware ecosystem.

The Current Ransomware Landscape

The rise of GLOBAL GROUP aligns with shifting dynamics in the RaaS landscape. As of June 2025, the Qilin ransomware group has emerged as a dominant force, accounting for 81 victims. Other significant players include Akira, Play, SafePay, and DragonForce, each with varying levels of victim counts.

Interestingly, while GLOBAL GROUP expands its influence, the total number of ransomware victims reported in June has seen a decline from May’s figures, dropping from 545 to 463. This marked a 15% decrease, with February recording the highest number of victims this year.

Ongoing Concerns in Cybersecurity

Despite this decline in victim counts, the cybersecurity landscape remains precarious. Geopolitical tensions and prominent cyber incidents underscore a heightened risk environment, prompting concerns among cybersecurity analysts. Information compiled by Optiv’s Global Threat Intelligence Center identifies a significant increase in ransomware activity, with 314 victims listed on various data leak sites in the first quarter of 2025 alone—representing a staggering 213% increase from the previous year.

Research indicates that ransomware operators consistently utilize familiar strategies to gain initial access, such as social engineering, exploitation of software vulnerabilities, and leveraging the IAB community.

As the landscape evolves, organizations must be vigilant and proactive in safeguarding their networks against evolving ransomware threats like GLOBAL GROUP.

spot_img

Related articles

Recent articles

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...

Fairlife resumes US production after ransomware attack, data breach confirmed

USA – The Coca-Cola Company has announced that its dairy subsidiary Fairlife has resumed most production across its four US facilities following a ransomware...