INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Global Group Ransomware Abuses WinMerge to Deploy Encryptor

| 2026-09-30 15:56 CRITICAL MEDIUM RANSOMWARE & EXTORTION
Executive Summary
AI-generated
On September 30, 2026, Global Group, a ransomware-as-a-service operation rebranding the legacy Black Lock and Mamona families, targeted large enterprises with payment-themed phishing emails that delivered a file-encrypting payload. The attackers used fake payment plans, malicious ISO files, and legitimate WinMerge application to deploy ransomware and extort victims. Approximately 100 organizations were affected by this attack. The operation worked by sending phishing emails posing as "Suggested Payment Plans" from generic Hotmail addresses, which led to the download of a malicious ISO file that launched [IOC HIDDEN • LOGIN REQUIRED], a legitimate file-comparison application. WinMerge then retrieved the Global Group ransomware encryptor and unpacked additional components into C:\Python27.x86, scanning local drives, network shares, and databases before encrypting files with the nZASJgT extension. The current status of this attack is that it has been ongoing since its discovery by researchers at Cofense Phishing Defense Center (PDC) on September 30, 2026.
Technical Mitigations AI-generated
• Block or hunt for the <a href="/auth/login?next=/detail/2Ov_9aABAhlSTKR_FLtI" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> file and its associated executable, as it is used to download <a href="/auth/login?next=/detail/2Ov_9aABAhlSTKR_FLtI" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>. • Use a reputable antivirus solution that can detect and block the <a href="/auth/login?next=/detail/2Ov_9aABAhlSTKR_FLtI" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> domain, which is used by Global Group's ransomware encryptor. • Monitor network shares and databases for suspicious activity related to the nZASJgT file extension, which is used by the malware after it has encrypted files.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

gl•••••.top
ha•••••.com
pr•••••.iso
dr•••••.sbs
RE•••••.txt
Pr•••••.exe
Wi•••••.exe
Pr•••••.pdf
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
‎2026/09/30
Threat actors used a malicious ISO file to deliver the Global Group ransomware encryptor via WinMerge, which was retrieved from globalsupportupdate.top.
organisation Global Group Ransomware Abuses WinMerge
organisation Deploy Encryptor
organisation Global Group
organisation ISO
organisation WinMerge
organisation Ransomware
organisation Black Lock
organisation Cofense
organisation Initial Access Brokers
organisation Hackread.com
organisation the Cofense
organisation PDF
organisation Global Group’s
Intelligence Sources