Skip to content

Global

Global ransomware is a ransomware-as-a-service operation that emerged in 2025 and is associated with the earlier Mamona and BlackLock branding through shared operational artifacts and actor overlap.

Profile source: Mallory opens in a new tab

Global

Family profile

Global ransomware is a ransomware-as-a-service operation that emerged in 2025 and is associated with the earlier Mamona and BlackLock branding through shared operational artifacts and actor overlap. It is a financially motivated double-extortion threat that steals data before encryption and pressures victims through leak-site exposure and time-limited negotiations. Reported victimology shows notable concentration in healthcare and manufacturing, and the operation has advertised itself to affiliates in multiple languages.

Global is notable for cross-platform support. Its lockers have been reported for Windows as well as Linux-oriented environments including ESXi, and broader reporting has also tied the family to NAS and BSD-based systems. The malware uses multithreaded encryption and employs ChaCha20-Poly1305, with behavior designed to accelerate impact by fully encrypting smaller files and partially encrypting larger ones. It can customize encrypted-file extensions, drop ransom notes broadly across the filesystem, print ransom notes, and alter the desktop wallpaper.

Post-compromise behavior includes data exfiltration, defense evasion, and lateral movement. Reported capabilities include attempts to terminate security tooling, delete shadow copies, and clear event logs before encryption. Global also supports LDAP-based propagation in Active Directory environments and token impersonation to move laterally and execute under stolen security contexts. Anti-analysis measures such as debugger checks and dead code have also been observed.

Affiliate intrusion activity has been linked to common ransomware tradecraft rather than a single exclusive access vector. Reporting indicates reliance on initial access brokers, password-spraying and brute-force activity against remote access infrastructure, and at least one documented intrusion chain beginning with phishing that delivered a remote access trojan before progressing through persistence, reconnaissance, privilege escalation, lateral movement, and exfiltration. The operation’s negotiation model includes high initial demands, leak threats, and promises of decryptors and post-payment support.

Capabilities

  • Brute Force
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Reconnaissance

Operational record

1
Indicators
1
YARA rules
1
Ransom notes
2
Leak sites
0 available

Published indicators

Session

1 total
  • 0532b290d16a48f8f81dc1a41c0840145aede477af674c56e6599507aa7f27933c

Recent claims

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.