Skip to main content

From Payment Plan to Ransomware - Inside a Global Group Attack

September 22, 2026

By: Iris Suaner, Cofense Phishing Defense Center

Highly sophisticated ransomware now targets industries worldwide. Today’s ransomware allows threat actors to infiltrate networks, encrypt confidential data, and hold critical systems hostage until a cryptocurrency ransom is paid. Worse, threat actors often employ “double extortion” techniques by stealing sensitive company data and threatening to publish data publicly if the ransom is not paid. By weaponizing a company’s digital assets against itself, ransomware stands as the most severe cybersecurity threat to modern business operations. 

The Cofense Phishing Defense Center (PDC) team has recently investigated a newly emerged Ransomware-as-a-Service (RaaS) operation organized by the Global Group, a financially motivated cybercriminal group running a Ransomware-as-a-Service (RaaS) platform. Targeting high-value, large-scale enterprises across different industries, escalating threats to the global digital economy. Global Group is a rebranding of the legacy Black Lock and Mamona ransomware families by inheriting an established backend infrastructure, reusing core code artifacts, and launching an immediately scalable extortion enterprise. They partner heavily with Initial Access Brokers (IABs) to purchase pre-compromised corporate credentials, allowing their affiliates to bypass perimeter defenses. Global Ransomware utilizes double extortion and threats of public data leaks as part of their aggressive negotiation tactics. 

Ransomware Delivery and Installation: 

Figure 1

Figure 1: Email Body

The ransomware was delivered through an email posing as a Suggested Payment Plan addressed to the recipient as a method of making the email appear legitimate, containing a PDF document sent using a generic Hotmail domain, suggesting that it contains the proposed payment plan for the open balance.

Figure 2 (1)

Figure 2: PDF Attachment

Upon opening the attached PDF file, a “Download” button was used as a lure to the recipient in downloading the malicious proposal file.

Figure 3

Figure 3: Malicious file download site

After clicking on the “Download” button on the PDF file, it redirected hXXps://driverupdate[.]sbs/access[.]php, where it lures the recipient to “Save a copy” of the malicious file.

Figure 4

Figure 4: Malicious executable file

The ISO file contains an executable file (Preview-9dc7.exe), an LNK file (Preview-9dc7.pdf), which is a shortcut or a pointer to the malicious executable file.

Figure 5

Figure 5: Legitimate WinMerge Process

Once the EXE file is executed, it spawns a WinMerge.exe process, which is an open-source file and folder comparison/merge tool for Windows, a legitimate application posing as the loader for the encryptor file, where it connects to hXXps://globalsupportupdate[.]top, as illustrated in Figure 7. 

Figure 6 (1)

Figure 6: C2 URL for downloading the encryption file

Figure 7 highlights the WinMerge.exe application’s connection to the malicious website hosting the encryptor file payload. 

Figure 7

Figure 7: Encrypted file payload

When manually accessing the web server hosting the payload, it downloads the enc.exe file containing the encryptor script. Once executed, this file scans the local drivers, network shares, and databases, disables security processes, and runs the cryptographic algorithm to encrypt the data it gathers while crippling the entire system. 

Figure 8

Figure 8: Encrypted file payload

Figure 9 shows the payload the ransomware drops into the system after the execution of the file enc.exe. It unpacks the ransomware’s toolkit and scripts needed in the C:\Python27.x86 file path. Dropping this payload allows the ransomware to run locally and execute commands. 

Figure 9 (1)

Figure 9: Encrypted Data

These .nZASJgT files are specific indicators of compromise (IoCs), which are the victim’s original files that have been successfully encrypted by the ransomware. Many ransomware families use unique file extensions to denote that the files have been successfully encrypted, and you can associate these files with this Global Ransomware sample. 

Figure 10

Figure 10: Ransom Note

After executing the ransomware encryption program, it changes the desktop wallpaper to a ransom note, which serves as the declaration of compromise, designed to set up control and initiate financial negotiations. It acts as the bridge between the technical execution of ransomware and the business extortion phase. This also identifies the profile of the threat actor or the cybercriminals behind the attack.

Figure 11

Figure 11: Ransom Instructions and Negotiation

The README.nZASJgT.txt is the ransom note’s detailed instructions on how to recover the encrypted files and the extortion demand. The ransom note provides steps that will be taken once the ransom is paid, including the decryption key for the files, promising the deletion of the extracted data with a detailed technical report of the attack path and vulnerabilities, a service package instruction for claiming the cyber insurance of the attack, and reputation management, which promises confidentiality of the attack within the organization. To elicit payments, the Global Group leverages convincing the victims to trust and reduce the hesitation of paying a ransom. They attempt to frame the extortion as a legitimate transactional business expense rather than a criminal act, designed to convince victims that they are dealing with a reliable business partner who will honor their end of the deal, for a more comfortable view of the ransom payment as a predictable path to risk mitigation and operational recovery of the compromised security.

 

The Ransomware-as-a-Service by the Global Group marks a dangerous escalation across all industries. Global Group represents a highly optimized evolution of the RaaS Model, built on the legacy of Black Lock and Mamona, and partnerships with Initial Access Brokers (IAB) that actively disarm endpoint security before dropping the payload and executing the Ransomware-as-a-Service, leveraging offering to extort victims for illicit payments. This ransomware cripples an organization’s infrastructure before they even realize a breach has occurred. Countering this threat requires organizations to proactively hunt for possible entry points in their security infrastructure against the Global Group and other cybercriminals.

Email(s) IOCs:

Stage 1: Discovered Malicious File(s): 

File Name: document_989399.pdf
MD5: 2abd445d3d60fd207b2c62bb0da3a42b
SHA256: d5004e079cb46db15a7d0b7ecebfa47bb8a1bc19e25749849a017b2a36705260
File Size: 1798 bytes


Stage 2: Discovered Malicious File(s): 

File Name: Preview-9dc7.iso
MD5: 9DB4B94589728B68D51BF83A90211CFE
SHA256: 00F70AE018E71F51060346AAA101209C24E34697BBFAFEC6B3612DB8D8127CB2
File Size: 3231744 bytes

File Name: Preview-9dc7.exe
MD5: 5DEE17E91F79BE742881324BCDF139A5
SHA256: 997CF28771FDE81C6BFC067EED1F19D0AD3554342D63D9469D3ADCDC1CA0FF31
File Size: 3175489 bytes

File Name: Preview-9dc7.pdf.lnk
MD5: 1E2C4CD35987EE217994149675784F9F
SHA256: 64388CDBFE48DCFF05EAA455892BCB3BFCAA3D43559EB7C65F6AC772810BE61E
File Size: 1483 bytes 

File Name: ptc1591.exe
 MD5: 20417846820741fa84c4571affb40e9c
 SHA256: 9fb468a79f88d9a250180749bfae97d4f310c8510f1f98cae359d95c2a62b4af
 File Size: 240128 bytes


Stage 2 – Observed Payload URL(s): 

Payload IP(s): 

hXXps://driverupdate[.]sbs/access[.]php?t=notes-a408df

172[.]67[.]175[.]15


Stage 2 – Observed Command & Control URL(s): 

Command & Control IP(s): 

hXXps://globalsupportupdate[.]top/enc[.]exe

104[.]21[.]92[.]70

hXXps://playmounthdom[.]top/

172[.]67[.]188[.]157




All third-party trademarks referenced by Cofense whether in logo form, name form or product form, or otherwise, remain the property of their respective holders, and use of these trademarks in no way indicates any relationship between Cofense and the holders of the trademarks. Any observations contained in this blog regarding circumvention of end point protections are based on observations at a point in time based on a specific set of system configurations. Subsequent updates or different configurations may be effective at stopping these or similar threats. Past performance is not indicative of future results.

 

The Cofense® and PhishMe® names and logos, as well as any other Cofense product or service names or logos displayed on this blog are registered trademarks or trademarks or trademarks of Cofense Inc.