Global Group is a financially motivated ransomware-as-a-service operation that emerged under this name in mid-2025. Formerly known as BlackLock or Black Lock, it is also associated with the legacy Mamona ransomware family through reused code and backend infrastructure. The operation targets large, high-value enterprises across multiple sectors, with healthcare, construction, and manufacturing disproportionately affected. Its targeting includes organizations in the United States. Global Group recruits within the ransomware ecosystem and works with initial access brokers to acquire access to compromised corporate networks. Global Group distributes ransomware through phishing campaigns using payment-related lures, PDF attachments, malicious disk images, and Windows shortcuts. Observed delivery chains abuse the legitimate WinMerge application to retrieve an encryptor; separate campaigns use PowerShell and Phorpiex to deliver its ransomware. The encryptor searches local drives, network shares, and databases, disables security processes, and encrypts victim files. The operation practices double extortion, combining encryption with threats to publish stolen data, although some observed ransomware payloads perform encryption entirely locally and do not themselves exfiltrate data. A distinctive feature is its AI-assisted chatbot for victim intake and ransom negotiations through a Tor-based portal. The chatbot automates communications and applies psychological pressure across time zones, reducing the negotiation workload for affiliates. Its extortion messaging presents decryption, intrusion details, cyber-insurance assistance, and confidentiality or reputation-management assurances as services offered in exchange for payment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
40 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-Service operation targeting large enterprises through phishing-delivered ransomware. It uses double extortion, encrypting victim files while stealing data and threatening publication, and also works with initial-access brokers to obtain access to compromised corporate networks.
Financially motivated ransomware-as-a-service operation, described as a rebrand of Black Lock and Mamona, reusing their backend infrastructure and code artifacts to support scalable extortion against large, high-value enterprises across industries.
Financially motivated RaaS operation targeting high-value, large-scale enterprises. The group is described as a rebranding built on legacy Black Lock and Mamona ransomware infrastructure and code artifacts. It uses initial-access brokers to acquire pre-compromised corporate credentials and conducts double-extortion ransomware operations.
Uses an independently verified AI negotiation chatbot for continuous victim intake and psychological pressure during ransomware extortion negotiations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.