Global ransomware is a ransomware-as-a-service operation that emerged in 2025 and is associated with the earlier Mamona and BlackLock branding through shared operational artifacts and actor overlap. It is a financially motivated double-extortion threat that steals data before encryption and pressures victims through leak-site exposure and time-limited negotiations. Reported victimology shows notable concentration in healthcare and manufacturing, and the operation has advertised itself to affiliates in multiple languages.
Global is notable for cross-platform support. Its lockers have been reported for Windows as well as Linux-oriented environments including ESXi, and broader reporting has also tied the family to NAS and BSD-based systems. The malware uses multithreaded encryption and employs ChaCha20-Poly1305, with behavior designed to accelerate impact by fully encrypting smaller files and partially encrypting larger ones. It can customize encrypted-file extensions, drop ransom notes broadly across the filesystem, print ransom notes, and alter the desktop wallpaper.
Post-compromise behavior includes data exfiltration, defense evasion, and lateral movement. Reported capabilities include attempts to terminate security tooling, delete shadow copies, and clear event logs before encryption. Global also supports LDAP-based propagation in Active Directory environments and token impersonation to move laterally and execute under stolen security contexts. Anti-analysis measures such as debugger checks and dead code have also been observed.
Affiliate intrusion activity has been linked to common ransomware tradecraft rather than a single exclusive access vector. Reporting indicates reliance on initial access brokers, password-spraying and brute-force activity against remote access infrastructure, and at least one documented intrusion chain beginning with phishing that delivered a remote access trojan before progressing through persistence, reconnaissance, privilege escalation, lateral movement, and exfiltration. The operation’s negotiation model includes high initial demands, leak threats, and promises of decryptors and post-payment support.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware rebrand referenced as the later name for Mamona in 2025.
Ransomware family referenced as a payload deployed via Phorpiex, including targeting in China and a later campaign spanning 21 countries.
Cross-platform ransomware operation targeting Windows/Linux/ESXi; extensions may be affiliate-defined/variable; linked to prior branding (Mamona/BlackLock).
Cross-platform ransomware operation/brand (Windows/Linux/ESXi) introduced as “GLOBAL GROUP”, with reporting tying it to earlier brands (Mamona/BlackLock).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.