Global — Ransomware Profile
GLOBAL GROUP is a ransomware-as-a-service operation that emerged in June 2025, reportedly launched by a known Russian-speaking threat actor, featuring AI-driven ransom negotiation and a mobile control panel for affiliates, targeting healthcare, oil and gas, industrial engineering, and automotive sectors.
IntelFusions coverage (25)
- Unit 42 found 97% of AI malware never leaves the lab 2026-08-25 · AI Security
- Malicious file names run commands in the nnn file manager 2026-08-19 · Vulnerabilities
- Hacker ran an AI agent fleet that backdoored 9,000 sites 2026-08-19 · AI Security
- Ransomware crews pile onto Italy's industrial firms 2026-08-13 · Cyber Incidents
- Ransomware crews hit Southeast Asian hotels, not hospitals 2026-08-09 · Cyber Incidents
- Ransomware hits Brazil's schools using stolen logins 2026-08-03 · Cyber Incidents
- LockBit floods its leak site with 26 victims in two days 2026-06-12 · Ransomware
- Fake Developer Tool Sites Hijack Downloads to Spread Stealers 2026-06-06 · Cyber Incidents
- OnePlus Websites Compromised via Abandoned AWS S3 Bucket — Stored XSS Active Across Multiple Domains 2026-03-17 · Vulnerabilities
- 166 Victims in 33 Countries: NightSpire's Global Expansion in Numbers 2026-03-15 · Ransomware
- Keymous+ Launches #Op_Epstein_Gulf: DDoS Campaign Hits Jordan, Oman, and Kuwait Government Portals 2026-03-04 · Cyber Incidents
- Two U.S. Cybersecurity Professionals Plead Guilty to ALPHV BlackCat Ransomware Attacks 2026-02-16 · Ransomware
- Operation DreamJob Targets European UAV and Defense Manufacturers: Lazarus Deploys ScoringMathTea via Trojanized Open-Source Tools 2026-02-16 · Nation-State
- DOJ Charges Two APT27 Hackers as Unit 42 Confirms Group Still Active Across 45 Countries in 2025 2026-02-16 · Nation-State
- MuddyWater Targets CFOs Globally with Firebase CAPTCHA Phishing, NetBird Abuse, and Hidden Admin Account Persistence 2026-02-16 · Nation-State
- Keymous+: Profile of a North African Hacktivist Collective Claiming 700+ DDoS Attacks in 2025 2026-02-16 · Cyber Incidents
- Eduard Benderskiy Named: The Former KGB Officer Who Shielded Evil Corp from Russian Law Enforcement 2026-02-16 · Cyber Incidents
- Handala Deploys Wiper Malware Disguised as CrowdStrike Fix During Global Outage 2026-02-16 · Cyber Incidents
- U.S. and Allied Agencies Warn of North Korean Andariel Espionage Campaign Targeting Defense and Nuclear Sectors 2026-02-16 · Nation-State
- TheMoon Botnet Powers Faceless Proxy Service with 40,000 Compromised SOHO Routers Across 88 Countries 2026-02-16 · Cyber Incidents
- NoName057(16) DDoSia 2024: FreeBSD and 32-bit Architecture Expansion, Machine GUID Fingerprinting, and Daily C2 Rotation Amid 20,000-Member Telegram Network 2026-02-16 · Cyber Incidents
- DEV-0537 (LAPSUS$): Social Engineering, SIM Swapping, and Insider Recruitment Power a Pure Extortion and Destruction Campaign 2026-02-16 · Cyber Incidents
- APT39: Iran's Personal Data Harvesting Machine Targets Telecom and Travel Industries for Surveillance Operations 2026-02-16 · Nation-State
- The Shadow Brokers NSA Equation Group Leak: EternalBlue, EternalRomance, DoublePulsar, and the Fuzzbunch Framework Released April 2017 2026-02-16 · Nation-State
- APT10's Operation Cloud Hopper: How China's MSS Weaponized IT Service Providers for Global Espionage 2026-02-16 · Nation-State
Recent claimed victims
Read the full analysis on IntelFusions