Title: Global Group Ransomware Operation Targets Enterprises via Phishing
A Ransomware-as-a-Service (RaaS) operation, identified as Global Group, has been reported to be targeting large enterprises through sophisticated phishing schemes that deliver file-encrypting malware. Recent findings shared by the Cofense Phishing Defense Center (PDC) reveal that attackers employ a combination of deceptive tactics, including fake payment plans, malicious ISO files, and the legitimate WinMerge application, to execute their attacks effectively.
The attack mechanism begins with an email masquerading as a “Suggested Payment Plan,” sent from an unremarkable Hotmail account. Included in this correspondence is a PDF attachment named document_989399.pdf, which features a “Download” button. Victims who click this button are redirected to a site called driverupdate.sbs, where they are prompted to download an ISO file.
Contained within the malicious ISO file, designated Preview-9dc7.iso, are the executable Preview-9dc7.exe and a shortcut labeled Preview-9dc7.pdf.lnk. Upon execution, the malware activates WinMerge.exe, a genuine file comparison tool, creating a façade of legitimacy. Notably, the WinMerge application itself is not compromised; rather, it is exploited as a delivery method for the ransomware. Researchers monitored WinMerge as it connected to the domain globalsupportupdate.top to retrieve the actual ransomware encryptor, enc.exe.
Once activated, the encryptor proceeds to extract additional components to C:\Python27.x86. It scans local drives, shared networks, and databases, disabling security features before encrypting files. The affected files are appended with the .nZASJgT extension. Furthermore, the malware alters the user’s desktop wallpaper to display a ransom note and creates a file named README.nZASJgT.txt, which outlines payment instructions and recovery options.
Global Group’s ransom notes reflect an increasingly business-oriented approach. According to Cofense, the notes not only offer decryption keys but also provide technical information about the breach, guidance for cyber insurance claims, and reputation management services. The perpetrators frame the extortion as a transactional business service, suggesting a dual-layered tactic where they employ intimidation through sensitive data theft while presenting themselves as capable service providers.
This operation is marked by the implementation of double extortion, where attackers not only encrypt data but also exfiltrate sensitive information, threatening to publish it unless their ransom demands are met. Organizations are urged to diligently monitor for signs of potential infection, including specific file names, extensions, and network activity associated with this threat.
The phishing campaign is part of a wider RaaS ecosystem, with Global Group collaborating with Initial Access Brokers (IABs). These brokers facilitate entry into compromised networks, thereby enabling affiliates to deploy ransomware more readily.
In terms of tactics, the attack appears to employ several techniques identified within the MITRE ATT&CK framework. Categories like initial access, specifically through phishing, and exploitation of trusted relationships, are evident. The abuse of legitimate applications highlights persistence and potential privilege escalation tactics. The Global Group operation underscores the evolving landscape of ransomware threats and the need for vigilance among enterprises to protect against such advanced cyberattacks.