GlobeImposter is a Windows ransomware family first observed in 2016 that imitates the Globe ransomware kit’s ransom-note style and file-extension conventions. It has appeared in many extension-based variants and has also been referred to in some reporting as LOLNEK or LOLKEK. Later activity indicates continued evolution and possible rebranding, including strong technical overlap with the TZW ransomware lineage.
GlobeImposter encrypts victim files and appends variant-specific extensions, with observed examples including .crypt, ..doc, ..726, .gif, and other campaign-specific suffixes. It commonly drops HTML or text ransom notes in affected directories and may include victim identifiers in encrypted data or filenames. Multiple analyses describe use of strong symmetric encryption for file content together with asymmetric key material for key protection, deletion of Volume Shadow Copies, termination of processes associated with office applications and databases to unlock files, and broad encryption of local, removable, and network-accessible storage.
The malware has demonstrated persistence mechanisms on Windows, including Run or RunOnce autoruns, and some variants relocate themselves into public or roaming-user locations before encryption. Certain samples use obfuscated JavaScript downloaders, runtime string decryption, and process replacement or hollowing-like execution to hinder analysis and detection. Some variants also clear Windows event logs and remove Remote Desktop client artifacts as anti-forensic measures.
Distribution has most commonly occurred through phishing and malspam campaigns carrying compressed archives with JavaScript downloaders or malicious Office documents with macros. GlobeImposter has also been delivered by the Necurs botnet, observed in exploit-kit chains including RIG, and associated with malvertising-driven delivery in some campaigns. Reporting also links limited GlobeImposter use to TA505, which historically distributed multiple ransomware families via large-scale phishing operations. Related derivatives or GlobeImposter-based strains have appeared in other operations, including PSCrypt and a GlobeImposter-based ONI encryptor.
Victimology is broad rather than sector-specific. GlobeImposter has affected enterprises, universities, and organizations across multiple countries, and some later reporting places it within the ransomware-as-a-service ecosystem. The family remains notable for its long operational lifespan, frequent superficial variant changes, and repeated reuse in spam- and intrusion-driven ransomware campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618). | Analysis shows that this file in turn downloads http://91[.]243[.]44[.]105/Lvmsrqz_Phdvabki.jpg, which turns out to be the encrypted GlobeImposter/Alpha865qqz payload.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618). | Analysis shows that this file in turn downloads http://91[.]243[.]44[.]105/Lvmsrqz_Phdvabki.jpg, which turns out to be the encrypted GlobeImposter/Alpha865qqz payload.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ils utiliseraient soit des trojans bancaires (notamment Dridex et TrickBot jusqu’à début 2018), soit des rançongiciels (notamment Locky, GlobeImposter et Philadelphia)
Our research links TZW ransomware to a known malware family called GlobeImposter (sometimes referred to as LOLNEK or LOLKEK).
...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...
26 distinct techniques documented for this family, organized by ATT&CK tactic.
They work similar to malicious macros seen in other malspam campaigns, using Powershell to retrieve a malware binary to infect a vulnerable Windows host.
it calls “vssadmin.exe Delete Shadows /All /Quiet” in an executable batch file to delete all shadows. In that batch file it also cleans up Remote Desktop information saved in the system registry
When the JS “IMG_8798.js” is executed, it downloads GlobeImposter from “hxxp://wendybull.com.au/87wefhi??JWbXSIl=JWbXSIl” and runs it.
It then creates its child process with the flag “CREATE_SUSPENDED”. It creates a suspended process, and later the code of the child process will be replaced with previously extracted code. This extracted code will be executed when the child process resumes its execution.
To prevent it from being analyzed easily, most strings and part of its APIs are encrypted. They are decrypted dynamically when running.
MITRE ATT&CK T1027.002 – Obfuscated Files or Information: Software Packing
This ransomware tries to pass as another family — WannaCry. The same thing was noticed with XData — based on stolen AES-NI codebase; PSCrypt — based on GlobeImposter; and NotPetya — disguised as Petya.
It then creates its child process with the flag “CREATE_SUSPENDED”. It creates a suspended process, and later the code of the child process will be replaced with previously extracted code. This extracted code will be executed when the child process resumes its execution.
To prevent the victim from restoring encrypted files from the Shadow Volume copies, it calls “vssadmin.exe Delete Shadows /All /Quiet” in an executable batch file to delete all shadows. In that batch file it also cleans up Remote Desktop information saved in the system registry as well as the file %UserProfile%\Documents\Default.rdp.
To release the user’s files locked by running processes, the cryptolocker terminates the following processes with the help of the ‘taskkill’ command: outlook ssms postgre 1c SQL excel word
CISA defines ransomware as “an ever-evolving form of malware designed to encrypt files on a device, rendering any files and the systems that rely on them unusable. Malicious actors then demand ransom in exchange for decryption.” | Once launched, the malware may connect to a command-and-control server to enable the criminals to move laterally across networks and encrypt and/or exfiltrate the organization’s data.
It then creates the ransom note shown in Figure 20. Note the use of the China.Helper@aol.com address, which we also saw in the instance of the “real” GlobeImposter infection discussed above. | kill$.exe drops a batch file into %TEMP%. Interestingly, this file contains comment strings in Chinese
79 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced mainly for comparison and misclassification; the article explicitly argues Maoloa is not GlobeImposter, despite similarities in ransom-note text and false detections.
Ransomware family analyzed here as a 2021 variant written in .NET/VB.NET, using heavy obfuscation, multi-stage in-memory execution, encoded image-resource payload delivery, and anti-analysis delays before loading additional DLL payloads and performing file encryption.
Ransomware active since 2016 that is typically distributed via phishing emails and RDP brute force attacks. It mimics Globe ransomware payloads, may disable antivirus and OS security features, may prevent system restoration, uses an embedded AES implementation instead of standard crypto APIs, dynamically constructs encrypted file extensions, removes RDP login logs after execution, and removes itself to reduce forensic artifacts.
Ransomware payload delivered via the SQL Server exploitation chain; it creates a ransom note executable and adds the .Globeimposter-Alpha865qqz extension to encrypted files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.