GlobeImposter is a Windows ransomware family first observed in 2016. Its name reflects its imitation of Globe ransomware’s ransom notes and encrypted-file naming conventions. It encrypts victim files, changes their extensions, and places ransom instructions in affected directories. Victims are directed to attacker-controlled Tor portals or contact channels to arrange payment for decryption. Some campaigns offer free decryption of a sample file as proof of recovery capability.
GlobeImposter variants can encrypt files across local, removable, and network drives, with some implementations using multiple encryption threads. Analyzed variants use AES-256-CBC for file encryption, while other versions incorporate RSA-2048-related key material. The malware terminates database and productivity-application processes to release files before encryption, excludes selected system and application directories, and deletes Windows Volume Shadow Copies to inhibit recovery. Documented variants also clear Windows event logs and remove Remote Desktop client artifacts. Persistence is established through Windows startup registry entries. Evasion techniques include encrypted strings and configuration data, runtime API resolution, and process hollowing that replaces code in a suspended child process before resuming execution.
Distribution includes phishing and malicious spam carrying compressed archives with JavaScript downloaders, as well as macro-enabled Word documents that retrieve payloads through PowerShell. The Necurs botnet distributed GlobeImposter in 2017, and the family has also been delivered through the RIG exploit kit and HookAds malvertising. GlobeImposter has been used by TA505 and was deployed by BruteSQL in 2021. It commonly affects small and mid-sized organizations, including intrusions through exposed Remote Desktop services. Early versions were supported by public decryption tools, but subsequent variants changed sufficiently that those tools could not recover their encrypted files.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618). | Analysis shows that this file in turn downloads http://91[.]243[.]44[.]105/Lvmsrqz_Phdvabki.jpg, which turns out to be the encrypted GlobeImposter/Alpha865qqz payload.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618). | Analysis shows that this file in turn downloads http://91[.]243[.]44[.]105/Lvmsrqz_Phdvabki.jpg, which turns out to be the encrypted GlobeImposter/Alpha865qqz payload.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA505 has used a wide variety of ransomware, such as Clop, Locky, Jaff, Bart, Philadelphia, and GlobeImposter, to encrypt victim files and demand a ransom payment.
BruteSQL is known for deploying various types of ransomware in the past, such as the GlobeImposter ransomware in 2021.
Our research links TZW ransomware to a known malware family called GlobeImposter (sometimes referred to as LOLNEK or LOLKEK).
...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...
25 distinct techniques documented for this family, organized by ATT&CK tactic.
“Dharma, Phobos, and GlobeImposter commonly target small and mid-sized organizations, often through exposed remote desktop services.”
They work similar to malicious macros seen in other malspam campaigns, using Powershell to retrieve a malware binary to infect a vulnerable Windows host.
it calls “vssadmin.exe Delete Shadows /All /Quiet” in an executable batch file to delete all shadows. In that batch file it also cleans up Remote Desktop information saved in the system registry
When the JS “IMG_8798.js” is executed, it downloads GlobeImposter from “hxxp://wendybull.com.au/87wefhi??JWbXSIl=JWbXSIl” and runs it.
It then creates its child process with the flag “CREATE_SUSPENDED”. It creates a suspended process, and later the code of the child process will be replaced with previously extracted code. This extracted code will be executed when the child process resumes its execution.
To prevent it from being analyzed easily, most strings and part of its APIs are encrypted. They are decrypted dynamically when running.
MITRE ATT&CK T1027.002 – Obfuscated Files or Information: Software Packing
This ransomware tries to pass as another family — WannaCry. The same thing was noticed with XData — based on stolen AES-NI codebase; PSCrypt — based on GlobeImposter; and NotPetya — disguised as Petya.
It then creates its child process with the flag “CREATE_SUSPENDED”. It creates a suspended process, and later the code of the child process will be replaced with previously extracted code. This extracted code will be executed when the child process resumes its execution.
To prevent the victim from restoring encrypted files from the Shadow Volume copies, it calls “vssadmin.exe Delete Shadows /All /Quiet” in an executable batch file to delete all shadows. In that batch file it also cleans up Remote Desktop information saved in the system registry as well as the file %UserProfile%\Documents\Default.rdp.
To release the user’s files locked by running processes, the cryptolocker terminates the following processes with the help of the ‘taskkill’ command: outlook ssms postgre 1c SQL excel word
“Successful data encryption also rose to 56 per cent of attacks” and recovery requires restoring data and systems after ransomware encrypts them.
It then creates the ransom note shown in Figure 20. Note the use of the China.Helper@aol.com address, which we also saw in the instance of the “real” GlobeImposter infection discussed above. | kill$.exe drops a batch file into %TEMP%. Interestingly, this file contains comment strings in Chinese
79 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family commonly aimed at small and mid-sized organizations, frequently through exposed remote desktop services; decryptor availability depends on the version.
Referenced mainly for comparison and misclassification; the article explicitly argues Maoloa is not GlobeImposter, despite similarities in ransom-note text and false detections.
Ransomware family analyzed here as a 2021 variant written in .NET/VB.NET, using heavy obfuscation, multi-stage in-memory execution, encoded image-resource payload delivery, and anti-analysis delays before loading additional DLL payloads and performing file encryption.
Ransomware active since 2016 that is typically distributed via phishing emails and RDP brute force attacks. It mimics Globe ransomware payloads, may disable antivirus and OS security features, may prevent system restoration, uses an embedded AES implementation instead of standard crypto APIs, dynamically constructs encrypted file extensions, removes RDP login logs after execution, and removes itself to reduce forensic artifacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.