Emerging Ransomware-as-a-Service, Supporting AI Driven Negotiation and Mobile Control Panel for Their Affiliates

July 16, 2025, 7:24 p.m.

Description

A new Ransomware-as-a-Service (RaaS) group called GLOBAL GROUP has emerged, likely a rebranding of the BlackLock RaaS operation. The group targets various sectors across the US and Europe, with a focus on healthcare providers. GLOBAL GROUP utilizes Initial Access Brokers to gain entry to vulnerable edge appliances and employs brute-force tools for Microsoft Outlook and RDWeb portals. Their ransom negotiation panel features AI-driven chatbots, enabling non-English-speaking affiliates to engage victims more effectively. The group offers an 85% revenue share to affiliates and provides a mobile-friendly control panel. GLOBAL GROUP's infrastructure has been traced to a Russia-based VPS provider, and their operations show similarities to previous Mamona ransomware activities.

Date

  • Created: July 16, 2025, 4:10 p.m.
  • Published: July 16, 2025, 4:10 p.m.
  • Modified: July 16, 2025, 7:24 p.m.

Indicators

  • b5e811d7c104ce8dd2509f809a80932540a21ada0ee9e22ac61d080dc0bd237d
  • 28f3de066878cb710fe5d44f7e11f65f25328beff953e00587ffeb5ac4b2faa8
  • 232f86e26ced211630957baffcd36dd3bcd6a786f3d307127e1ea9a8b31c199f
  • 1f6640102f6472523830d69630def669dc3433bbb1c0e6183458bd792d420f8e
  • a8c28bd6f0f1fe6a9b880400853fc86e46d87b69565ef15d8ab757979cd2cc73
  • 193.19.119.4
  • 185.158.113.114
  • vg6xwkmfyirv3l6qtqus7jykcuvgx6imegb73hqny2avxccnmqt5m2id.onion
  • gdbkvfe6g3whrzkdlbytksygk45zwgmnzh5i2xmqyo3mrpipysjagqyd.onion

Attack Patterns

Additional Informations

  • Healthcare
  • Australia
  • United Kingdom of Great Britain and Northern Ireland
  • Brazil
  • United States of America