Skip to content

Globeimposter

GlobeImposter is a Windows ransomware family first observed in 2016 that imitates the Globe ransomware kit’s ransom-note style and file-extension conventions.

Profile source: Mallory opens in a new tab

Globeimposter

Family profile

GlobeImposter is a Windows ransomware family first observed in 2016 that imitates the Globe ransomware kit’s ransom-note style and file-extension conventions. It has appeared in many extension-based variants and has also been referred to in some reporting as LOLNEK or LOLKEK. Later activity indicates continued evolution and possible rebranding, including strong technical overlap with the TZW ransomware lineage.

GlobeImposter encrypts victim files and appends variant-specific extensions, with observed examples including .crypt, ..doc, ..726, .gif, and other campaign-specific suffixes. It commonly drops HTML or text ransom notes in affected directories and may include victim identifiers in encrypted data or filenames. Multiple analyses describe use of strong symmetric encryption for file content together with asymmetric key material for key protection, deletion of Volume Shadow Copies, termination of processes associated with office applications and databases to unlock files, and broad encryption of local, removable, and network-accessible storage.

The malware has demonstrated persistence mechanisms on Windows, including Run or RunOnce autoruns, and some variants relocate themselves into public or roaming-user locations before encryption. Certain samples use obfuscated JavaScript downloaders, runtime string decryption, and process replacement or hollowing-like execution to hinder analysis and detection. Some variants also clear Windows event logs and remove Remote Desktop client artifacts as anti-forensic measures.

Distribution has most commonly occurred through phishing and malspam campaigns carrying compressed archives with JavaScript downloaders or malicious Office documents with macros. GlobeImposter has also been delivered by the Necurs botnet, observed in exploit-kit chains including RIG, and associated with malvertising-driven delivery in some campaigns. Reporting also links limited GlobeImposter use to TA505, which historically distributed multiple ransomware families via large-scale phishing operations. Related derivatives or GlobeImposter-based strains have appeared in other operations, including PSCrypt and a GlobeImposter-based ONI encryptor.

Victimology is broad rather than sector-specific. GlobeImposter has affected enterprises, universities, and organizations across multiple countries, and some later reporting places it within the ransomware-as-a-service ecosystem. The family remains notable for its long operational lifespan, frequent superficial variant changes, and repeated reuse in spam- and intrusion-driven ransomware campaigns.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence

Operational record

1
YARA rules
3
Leak sites
0 available

Reported operators

Threat actors

3 named in public reporting
TA505

ils utiliseraient soit des trojans bancaires (notamment Dridex et TrickBot jusqu’à début 2018), soit des rançongiciels (notamment Locky, GlobeImposter et Philadelphia)

G0092

Our research links TZW ransomware to a known malware family called GlobeImposter (sometimes referred to as LOLNEK or LOLKEK).

SectorJ04

...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...

Exploited software

Vulnerabilities linked to Globeimposter

2 CVEs

MITRE ATT&CK

Globeimposter in ATT&CK

40 distinct techniques

Reporting

Research mentioning Globeimposter

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

Aug 12
Hookphish

Ransomware Group clop Hits: LARGAN.COM.TW

Jan 1
Sophos Threat Research

OODA: X-Ops Takes On Burgeoning SQL Server Attacks | SOPHOS

Attackers targeted externally exposed, unpatched Microsoft SQL Server systems by exploiting CVE-2019-1068 and CVE-2020-0618, then delivered a mix of malware and ransomware through shared infrastructure and tooling. Sophos linked the intrusions through common ingress methods, command-and-control servers, PowerShell downloaders, a .NET downloader, Remcos RAT, the Kill$ cleaner, and 7zip SFX-based loaders, with ransomware payloads including TargetCompany/Mallox and GlobeImposter/Alpha865qqz. Most victims were observed in Asia, with additional cases in the Americas, and Chinese-language comments in some tools suggested the operators may be based in Asia. In one investigated case, the attackers returned after an earlier ransomware incident because the SQL Server remained unpatched, showing how exposed systems can be repeatedly compromised until the root weakness is fixed. Sophos said its defenses blocked follow-on payload delivery and prevented lateral movement, data exfiltration, and further ransom escalation, while responders also identified IOBit Unlocker as an attempted anti-security utility. Continued traffic to a fake KMSAuto-themed download site helped tie the customer incident to the wider campaign.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.