Overview
Global is a ransomware-as-a-service (RaaS) operation that emerged publicly in June 2025 and quickly established itself as a notable player in the cybercrime ecosystem. The group was initially promoted on the RAMP underground forum by a Russian-speaking actor operating under the alias “$$$,” who introduced the service under the misspelled name “GLOBALY” before formally launching the Global ransomware group AKA GLOBAL RaaS, later that month.
The operation appears closely linked to the former BlackLock ransomware operation, with additional associations identified with Mamona RaaS. Infrastructure reuse, malware similarities, shared operational artifacts, and operational security failures have contributed to this assessment. Both Global and BlackLock have been connected to the Russian VPS provider IpServer, while analysts identified common mutex values within malware samples and exposed infrastructure overlap between their leak-site operations.
Global distinguishes itself through a mature affiliate ecosystem rather than through purely technical innovation. The operation provides affiliates with a dedicated negotiation platform, mobile management capabilities, and AI-assisted victim communication features designed to streamline extortion workflows. The group also advertises highly competitive affiliate compensation, offering partners up to 80–85% of ransom proceeds.
Unlike ransomware groups focused solely on encryption, Global has built its model around operational scalability: acquiring access through brokers, automating negotiation processes, and enabling affiliates to execute campaigns with limited technical overhead.
Emergence and Attribution
Global has no confirmed nation-state affiliation and is assessed as a financially motivated cybercriminal operation. Current intelligence suggests that the group represents a continuation or rebranding of earlier ransomware activity rather than a completely new threat actor.

The strongest links connect Global to BlackLock, with Mamona RaaS also appearing within the same operational ecosystem. These relationships are supported by:
- Shared hosting infrastructure
- Similar ransomware development patterns
- Common malware artifacts
- Leak-site infrastructure exposure caused by OPSEC failures
The reuse of infrastructure and tooling suggests a shared criminal ecosystem where ransomware brands may evolve through rebranding, affiliate migration, or operator changes rather than operating as isolated entities.
For defenders, this matters because historical intelligence associated with BlackLock or related ransomware families may provide useful context when investigating Global activity.
Ransomware and Malware Ecosystem
Global ransomware is written in Go and uses ChaCha20-Poly1305 encryption. The malware supports cross-platform deployment, including Windows, Linux, ESXi, and NAS environments, allowing affiliates to target a wider range of enterprise infrastructure.

The group has continued expanding its ecosystem beyond ransomware deployment with the introduction of custom tooling.
A major addition was WorldThief Stealer, announced on the RAMP forum on July 20, 2025. Marketed as an affiliate-focused data theft tool, WorldThief strengthens Global’s double-extortion capability by improving the collection and exfiltration phase before encryption.
WorldThief includes several features designed to increase operational efficiency:
- Quiet Mode: Allows execution with reduced user visibility.
- Bandwidth Throttling: Limits transfer speed to reduce detection risk.
- Targeted Patterns: Allows affiliates to focus collection on specific files or directories.
- Exclude Patterns: Removes unnecessary data collection to improve efficiency.
- Maximum File Size Controls: Prevents collection of unusually large files that could increase suspicion.
- Raw TCP Mode: Enables direct data transfer channels outside traditional protocols.
The addition of dedicated stealer tooling demonstrates Global’s transition from a ransomware payload provider into a broader extortion platform.
Affiliate Model and Criminal Ecosystem
Global operates a structured affiliate program designed to lower barriers for cybercriminal participation. The actor “$$$” actively recruits operators through the RAMP underground forum, encouraging penetration testers and experienced intrusion teams to join the program. The group advertises:
- Flexible affiliate participation
- Access to negotiation infrastructure
- No upfront deposit requirements
- Internal support for ransom negotiations

The group’s business model reflects the wider ransomware market shift toward specialization:
- Initial access brokers obtain network access.
- Affiliates deploy ransomware and manage operations.
- Global provides infrastructure, tooling, and negotiation support.
This division of labour allows campaigns to scale quickly while reducing operational complexity for individual affiliates.
Targeting Profile
Global demonstrates broad opportunistic targeting across multiple industries and geographic regions. Rather than focusing on a single sector, the group appears to prioritize organizations with valuable data, exposed infrastructure, and weak external security controls.
Target Industries
Observed targeting includes:

Geographic Targeting
Global activity has been observed across 18 countries.

The geographic spread indicates a globally oriented affiliate operation rather than a campaign restricted to a specific region.
Initial Access and Attack Chain
Global relies on purchased access, credential abuse, and exploitation of exposed enterprise infrastructure to gain initial access. Affiliates commonly use Initial Access Brokers (IABs), compromised VPN credentials, OWA, RDWeb, RDP services, and vulnerabilities in edge security appliances such as Fortinet, Palo Alto, and Cisco products. This access-driven model allows operators to bypass traditional reconnaissance and exploitation stages while accelerating intrusion operations.

After gaining entry, Global maintains persistence through valid accounts, remote services, and registry-based execution mechanisms, allowing attackers to blend into legitimate administrative activity. The group uses Windows commands, malicious services, and SMB administrative shares for execution and lateral movement, enabling rapid ransomware deployment across connected systems.
Global employs multiple defense-evasion techniques, including disabling security tools, removing logs, self-deleting payloads, and using stealth-focused tooling such as WorldThief. The final stage combines data theft, encryption, and recovery disruption to maximize extortion pressure, with ransomware support extending across Windows, Linux, ESXi, and NAS environments.
The group operates a Tor-based leak-site infrastructure for victim publication and extortion. However, OPSEC failures exposed backend infrastructure, including the IP address 193.19.119[.]4, linked to the Russian VPS provider IpServer. This highlights how infrastructure reuse and operational mistakes can provide valuable intelligence opportunities against even established ransomware operations.
Recent Tooling Developments
Impersonation Mode
The Global Windows locker introduced an Impersonation Mode, designed to provide additional execution flexibility and improve stealth during deployment.
Remote Execution Changes
The group shifted from traditional service-based execution methods toward remote execution using Windows Management Instrumentation (WMI), improving lateral reach and reducing reliance on more easily monitored mechanisms.
Custom Stealer Development
The operator “$$$” also announced development of a custom C-based stealer intended to improve speed and usability for affiliates. These developments indicate continued investment into making Global’s platform easier to operate at scale.
Conclusion
The Global group has quickly established itself as a mature ransomware-as-a-service (RaaS) operation by combining a scalable affiliate model, AI-assisted negotiations, and cross-platform ransomware capabilities. Its suspected ties to BlackLock and Mamona highlight the interconnected nature of the ransomware ecosystem, where operators, infrastructure, and tooling frequently overlap. For defenders, the global ransomware group reflects a modern extortion model built on purchased access, automation, and operational efficiency rather than technical complexity.
Cyble helps organizations stay protected from threat actors like the Global ransomware group and other adversaries. With its AI-powered Cyber Threat Intelligence, Attack Surface Management, Dark Web Monitoring, and Digital Risk Protection, security teams can identify risks early and respond faster.
Want to see how it works or want to explore how Cyble threat intelligence catches threat actors before they can reach your environment? Schedule your personalized demo today!
MITRE ATT&CK Techniques Associated with Global Ransomware Group

- Valid Accounts (T1078 | Initial Access): Uses credentials obtained from Initial Access Brokers (IABs) or compromised authentication portals, including OWA, RDWeb, and VPN gateways, to gain unauthorized access while blending into legitimate user activity.
- External Remote Services (T1133 | Initial Access): Exploits exposed RDP services and VPN gateways, often using brute-force tools, to establish an initial foothold in enterprise networks lacking strong authentication controls.
- Exploit Public-Facing Application (T1190 | Initial Access): Targets internet-facing Fortinet, Palo Alto, and Cisco appliances by exploiting known vulnerabilities or misconfigurations to gain initial access.
- Windows Command Shell (T1059.003 | Execution): Uses Windows command-line utilities to deploy ransomware payloads and execute malicious operations across compromised environments.
- Service Execution (T1569.002 | Execution): Creates malicious Windows services to automate ransomware deployment and facilitate lateral movement across enterprise networks.
- Registry Run Keys / Startup Folder (T1547.001 | Persistence): Establishes persistence by configuring payloads to execute automatically during system startup or user logon.
- Process Injection (T1055 | Privilege Escalation): Likely injects malicious code into legitimate processes to elevate privileges and evade detection, consistent with observed ransomware tradecraft.
- Obfuscated Files or Information (T1027 | Defense Evasion): Uses WorldThief’s Quiet Mode, bandwidth throttling, and Raw TCP communication to reduce visibility and evade endpoint detection.
- Impair Defenses (T1562 | Defense Evasion): Terminates security services, removes logs, and self-deletes components to hinder detection and forensic investigation.
- Brute Force (T1110 | Credential Access): Performs brute-force attacks against OWA, RDWeb, and VPN services using automated tooling to obtain valid credentials.
- File and Directory Discovery (T1083 | Discovery): Enumerates files and directories using targeted collection rules to identify high-value data before exfiltration or encryption.
- SMB/Windows Admin Shares (T1021.002 | Lateral Movement): Uses SMB and Windows administrative shares to propagate ransomware across domain-connected systems.
- Automated Collection (T1119 | Collection): Leverages WorldThief to automate the collection of sensitive data using configurable file type, size, and directory filters.
- Exfiltration Over C2 Channel (T1041 | Exfiltration): Exfiltrates stolen data over Raw TCP channels to attacker-controlled infrastructure, reducing reliance on traditional network protocols.
- Internal Proxy (T1090.001 | Command and Control): Uses Tor hidden services to host its leak site and conceal command-and-control infrastructure, although OPSEC failures have exposed backend infrastructure linked to IpServer.
- Data Encrypted for Impact (T1486 | Impact): Encrypts files across Windows, Linux, ESXi, and NAS environments before dropping ransom notes to initiate extortion.
- Inhibit System Recovery (T1490 | Impact): Attempts to disable recovery mechanisms, including Volume Shadow Copies, to reduce restoration options and increase ransom leverage.