INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
| 2026-09-30 15:56 CRITICAL MEDIUM RANSOMWARE & EXTORTION
Executive Summary
AI-generated
On September 30, 2026, Global Group, a ransomware-as-a-service operation rebranding the legacy Black Lock and Mamona families, targeted large enterprises with payment-themed phishing emails that delivered a file-encrypting payload. The attackers used fake payment plans, malicious ISO files, and legitimate WinMerge application to deploy ransomware and extort victims. Approximately 100 organizations were affected by this attack. The operation worked by sending phishing emails posing as "Suggested Payment Plans" from generic Hotmail addresses, which led to the download of a malicious ISO file that launched [IOC HIDDEN • LOGIN REQUIRED], a legitimate file-comparison application. WinMerge then retrieved the Global Group ransomware encryptor and unpacked additional components into C:\Python27.x86, scanning local drives, network shares, and databases before encrypting files with the nZASJgT extension. The current status of this attack is that it has been ongoing since its discovery by researchers at Cofense Phishing Defense Center (PDC) on September 30, 2026.
Technical Mitigations AI-generated
• Block or hunt for the <a href="/auth/login?next=/detail/2Ov_9aABAhlSTKR_FLtI" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> file and its associated executable, as it is used to download <a href="/auth/login?next=/detail/2Ov_9aABAhlSTKR_FLtI" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>.
• Use a reputable antivirus solution that can detect and block the <a href="/auth/login?next=/detail/2Ov_9aABAhlSTKR_FLtI" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> domain, which is used by Global Group's ransomware encryptor.
• Monitor network shares and databases for suspicious activity related to the nZASJgT file extension, which is used by the malware after it has encrypted files.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
gl•••••.top
ha•••••.com
pr•••••.iso
dr•••••.sbs
RE•••••.txt
Pr•••••.exe
Wi•••••.exe
Pr•••••.pdf
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
2026/09/30
Threat actors used a malicious ISO file to deliver the Global Group ransomware encryptor via WinMerge, which was retrieved from globalsupportupdate.top.
Click on any entity below to view its context and source!
organisation
Global Group Ransomware Abuses WinMerge
Global Group Ransomware Abuses WinMerge to Deploy Encryptor.
organisation
Deploy Encryptor
Global Group Ransomware Abuses WinMerge to Deploy Encryptor.
organisation
Global Group
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.
A Ransomware-as-a-Service (
RaaS
) operation known as Global Group is targeting large enterprises with phishing emails that deliver a file-encrypting payload.
organisation
ISO
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.
Research shared with Hackread.com by the Cofense Phishing Defense Center (PDC) shows attackers using a fake payment plan, a malicious ISO file and the legitimate WinMerge application during the infection chain.
organisation
WinMerge
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.
Research shared with Hackread.com by the Cofense Phishing Defense Center (PDC) shows attackers using a fake payment plan, a malicious ISO file and the legitimate WinMerge application during the infection chain.
organisation
Ransomware
A Ransomware-as-a-Service (
RaaS
) operation known as Global Group is targeting large enterprises with phishing emails that deliver a file-encrypting payload.
organisation
Black Lock
Cofense
describes Global Group
as “a rebranding of the legacy Black Lock and Mamona ransomware families,” with the operation reusing existing infrastructure and code.
organisation
Cofense
Cofense observed WinMerge connecting to
globalsupportupdate.top
to retrieve
enc.exe
, the ransomware encryptor.
organisation
Initial Access Brokers
Global Group also works with Initial Access Brokers (IABs), which sell access to already-compromised corporate networks, giving affiliates another route to deploy ransomware.
organisation
Hackread.com
Research shared with Hackread.com by the Cofense Phishing Defense Center (PDC) shows attackers using a fake payment plan, a malicious ISO file and the legitimate WinMerge application during the infection chain.
organisation
the Cofense
Research shared with Hackread.com by the Cofense Phishing Defense Center (PDC) shows attackers using a fake payment plan, a malicious ISO file and the legitimate WinMerge application during the infection chain.
organisation
PDF
Its
PDF attachment
,
document_989399.pdf
, contains a “Download” button.
organisation
Global Group’s
Global Group’s ransom message presents payment, file recovery and other services to the victim.
Intelligence Sources
AlienVault OTX
2026-09-30
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
AlienVault OTX
HackRead
2026-09-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T12:07
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
Global Group Ransomware Abuses WinMerge
entity
3x
tactic
Cyber Operation Type
Ransomware
tactic
Contextual Telemetry
Context Block
2 METRICS
industry
Targeted Sector
Defense
sector
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.