Emerging Threat: Understanding GLOBAL GROUP Ransomware
Cybersecurity experts have recently uncovered a new ransomware-as-a-service (RaaS) operation named GLOBAL GROUP. This organization has rapidly gained notoriety since its emergence in June 2025, with attacks reported across various sectors in Australia, Brazil, Europe, and the United States.
The Rise of GLOBAL GROUP
Prominently showcased on the Ramp4u forum by a threat actor known as $$$, GLOBAL GROUP seems to be a rebranding of the previously operational BlackLock RaaS. Earlier this year, a data leak site associated with BlackLock was defaced by the DragonForce ransomware cartel, leading to speculation that GLOBAL GROUP represents a new phase in this ongoing cybercriminal saga. It is noteworthy that BlackLock itself was a rebranding of an earlier scheme called Eldorado.
Tactics Employed by GLOBAL GROUP
The financial motivations driving GLOBAL GROUP influence its operational strategies. The group relies heavily on initial access brokers (IABs) to deploy its ransomware. By taking advantage of vulnerable edge appliances from well-known vendors such as Cisco, Fortinet, and Palo Alto Networks, they effectively target organizational weak points. Additionally, the use of brute-force utilities to access Microsoft Outlook and RDWeb portals adds another layer to their deployment methods.
Exploiting Corporate Vulnerabilities
$$$ has successfully secured Remote Desktop Protocol (RDP) or web shell access to several corporate networks, including those of law firms. This access enables them to deploy post-exploitation tools, conduct lateral movements within networks, siphon sensitive data, and ultimately unleash ransomware payloads.
By outsourcing the infiltration phase to other cybercriminals, GLOBAL GROUP allows its affiliates to focus on the more complex tasks of delivering ransomware, negotiating with victims, and extorting funds, rather than the intricate process of penetrating corporate defenses.
RaaS Features and Revenue Model
The GLOBAL GROUP RaaS platform includes a negotiation portal accompanied by an affiliate management panel. These tools are designed to assist cybercriminals in managing their victims, crafting ransomware payloads for various platforms—such as VMware ESXi, NAS, BSD, and Windows—and monitoring the overall operational progress. To attract more affiliates, GLOBAL GROUP offers a lucrative revenue-sharing model, reportedly providing up to 85% returns.
The negotiation panel also incorporates an AI-driven chatbot system, enabling effective communication with victims regardless of their language, thereby broadening the pool of potential affiliates.
Victim Profile and Industry Impact
As of mid-July 2025, GLOBAL GROUP has claimed 17 victims across various sectors, including healthcare, oil and gas, industrial machinery, automotive repair, and business process outsourcing. This diverse target list illustrates the broad scope of their operational ambitions.
The association with previously known RaaS entities such as BlackLock and Mamona further enriches the narrative surrounding GLOBAL GROUP. Evidence points to them sharing the same Russian VPS provider, IpServer, and similarities in source code with Mamona Ransomware. This evolution marks a strategic pivot aimed at enhancing operational reach, monetization potential, and competitiveness within the ransomware ecosystem.
The Current Ransomware Landscape
The rise of GLOBAL GROUP aligns with shifting dynamics in the RaaS landscape. As of June 2025, the Qilin ransomware group has emerged as a dominant force, accounting for 81 victims. Other significant players include Akira, Play, SafePay, and DragonForce, each with varying levels of victim counts.
Interestingly, while GLOBAL GROUP expands its influence, the total number of ransomware victims reported in June has seen a decline from May’s figures, dropping from 545 to 463. This marked a 15% decrease, with February recording the highest number of victims this year.
Ongoing Concerns in Cybersecurity
Despite this decline in victim counts, the cybersecurity landscape remains precarious. Geopolitical tensions and prominent cyber incidents underscore a heightened risk environment, prompting concerns among cybersecurity analysts. Information compiled by Optiv’s Global Threat Intelligence Center identifies a significant increase in ransomware activity, with 314 victims listed on various data leak sites in the first quarter of 2025 alone—representing a staggering 213% increase from the previous year.
Research indicates that ransomware operators consistently utilize familiar strategies to gain initial access, such as social engineering, exploitation of software vulnerabilities, and leveraging the IAB community.
As the landscape evolves, organizations must be vigilant and proactive in safeguarding their networks against evolving ransomware threats like GLOBAL GROUP.


