GLOBAL GROUP is a ransomware-as-a-service operation assessed to be the latest branding of the same criminal enterprise previously known as Eldorado or El Dorado and later BlackLock. The group is associated with the Russian-language cybercriminal ecosystem and has operated on the RAMP forum to recruit affiliates, advertise ransomware capabilities, and support extortion operations. Available reporting characterizes it as a financially motivated, Russian-speaking criminal operation rather than a nation-state actor. The operation uses an affiliate model and has offered cross-platform ransomware for Windows, Linux, and VMware ESXi environments, with particular emphasis on virtualization infrastructure. Reported tradecraft includes social-engineering-based initial access using phishing-delivered shortcut files and command execution through native system tools, followed by persistence, local execution of the ransomware, backup destruction, and encryption of virtual machine assets. In ESXi-focused intrusions, the group has been linked to activity such as datastore enumeration, termination of running virtual machines, and encryption of hypervisor-hosted workloads. Reporting also indicates use of Go-based ransomware builders and modern encryption schemes for cross-platform lockers. GLOBAL GROUP has been notable for integrating AI-assisted victim communications into its extortion workflow. Its negotiation infrastructure has been described as using an AI chatbot to automate and tailor ransom discussions based on victim characteristics, reducing affiliate workload and increasing scale. The group has also advertised AI-assisted chat capabilities for analyzing victim organizations and customizing negotiation pressure. Separate reporting describes a variant or campaign in which the ransomware performs activity locally and is compatible with air-gapped environments, with no data exfiltration observed; however, other reporting ties the broader operation to leak-site activity and extortion behavior, indicating that tactics may vary by affiliate or campaign. Victimology is broad rather than tightly sector-specific, but healthcare, construction, and manufacturing have been disproportionately affected in observed reporting. Additional targeting has included organizations in the United States and Europe across healthcare, manufacturing, education, government, and media. Known aliases and historical names include Eldorado, El Dorado, and BlackLock.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service operation focused on ESXi and broader hypervisor attacks, using phishing/LNK-based initial access, loaders, Active Directory compromise, lateral movement, and cross-platform encryptors to conduct recovery-denial extortion against organizations.
Ransomware crew delivered via phishing/LNK → PowerShell → Phorpiex dropper chain; notable for local-only activity (air-gapped compatible) and no data exfiltration.
GLOBAL Group is a ransomware group utilizing RAMP for collaboration, recruitment, and operational coordination.
Global Group RaaS is a ransomware-as-a-service operation known for integrating AI-driven features, such as AI-Assisted Chat, to enhance attacker-to-victim communications and tailor extortion demands. The group targets a range of industries, with a focus on healthcare, construction, and manufacturing.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.