Cofense Details Global Group Ransomware Attack Chain and Indicators

Summary
Cofense describes a Global Group ransomware campaign delivered through a fake payment-plan email. The attack uses a PDF lure, ISO and executable files, then encrypts data and threatens victims with public leaks.
Key points
- Cofense reports that Global Group operates a ransomware-as-a-service operation linked to the legacy Black Lock and Mamona ransomware families.
- The campaign email posed as a suggested payment plan and included a PDF with a download lure leading to a malicious ISO file.
- The ISO contained an executable and a shortcut; the executable launched legitimate WinMerge, which connected to a site hosting the encryptor.
- The encryptor scans local drives, network shares, and databases, disables security processes, and encrypts data. Encrypted files use the .nZASJgT extension.
- The ransom note offers decryption and other purported services while threatening to publish extracted data if victims do not pay.
- Cofense says the group works with initial access brokers that supply pre-compromised corporate credentials.
- The report provides file hashes and URLs/IP addresses associated with the delivery and command-and-control infrastructure.
Article Details
- Attack Vectors
- A payment-plan-themed email delivered a malicious PDF attachment.
- The PDF's Download button redirected recipients to a malicious file-download site, where they were prompted to save an ISO file.
- The ISO contained an executable and a shortcut pointing to that executable. Running it spawned WinMerge.exe, which connected to a site hosting the encryptor payload.
- The article says Global Group partners with Initial Access Brokers to purchase pre-compromised corporate credentials for its affiliates.
- Defensive Notes
- Cofense recommends proactively hunting for possible entry points in organizational security infrastructure.
- Cofense cautions that its observations about circumventing endpoint protections reflect specific configurations at a point in time; updates or different configurations may stop similar threats.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 104[.]21[.]92[.]70 | IP listed with an observed command-and-control URL. |
| IPV4 | 172[.]67[.]175[.]15 | IP listed with the observed payload URL. |
| IPV4 | 172[.]67[.]188[.]157 | IP listed with an observed command-and-control URL. |
| MD5 | 1e2c4cd35987ee217994149675784f9f | MD5 of the malicious Preview-9dc7.pdf.lnk shortcut. |
| MD5 | 20417846820741fa84c4571affb40e9c | MD5 of ptc1591.exe, listed among discovered malicious files. |
| MD5 | 2abd445d3d60fd207b2c62bb0da3a42b | MD5 of the malicious document_989399.pdf attachment. |
| MD5 | 5dee17e91f79be742881324bcdf139a5 | MD5 of the malicious Preview-9dc7.exe file. |
| MD5 | 9db4b94589728b68d51bf83a90211cfe | MD5 of the malicious Preview-9dc7.iso file. |
| SHA256 | 00f70ae018e71f51060346aaa101209c24e34697bbfafec6b3612db8d8127cb2 | SHA-256 of the malicious Preview-9dc7.iso file. |
| SHA256 | 64388cdbfe48dcff05eaa455892bcb3bfcaa3d43559eb7c65f6ac772810be61e | SHA-256 of the malicious Preview-9dc7.pdf.lnk shortcut. |
| SHA256 | 997cf28771fde81c6bfc067eed1f19d0ad3554342d63d9469d3adcdc1ca0ff31 | SHA-256 of the malicious Preview-9dc7.exe file. |
| SHA256 | 9fb468a79f88d9a250180749bfae97d4f310c8510f1f98cae359d95c2a62b4af | SHA-256 of ptc1591.exe, listed among discovered malicious files. |
| SHA256 | d5004e079cb46db15a7d0b7ecebfa47bb8a1bc19e25749849a017b2a36705260 | SHA-256 of the malicious document_989399.pdf attachment. |
| URL | hxxps[:]//driverupdate[.]sbs/access[.]php | Malicious file-download page reached through the PDF's Download button. |
| URL | hxxps[:]//driverupdate[.]sbs/access[.]php?t=notes-a408df | Observed malicious payload URL. |
| URL | hxxps[:]//globalsupportupdate[.]top | Malicious site contacted by WinMerge.exe and described as hosting the encryptor payload. |
| URL | hxxps[:]//globalsupportupdate[.]top/enc[.]exe | Observed command-and-control URL for the encryptor payload. |
| URL | hxxps[:]//playmounthdom[.]top/ | Observed command-and-control URL. |
MITRE ATT&CK
T1036.007 · Double File ExtensionThe ISO included a shortcut named Preview-9dc7.pdf.lnk that pointed to the malicious executable.T1078 · Valid AccountsThe article says Global Group purchases pre-compromised corporate credentials through Initial Access Brokers so affiliates can bypass perimeter defenses.T1105 · Ingress Tool TransferWinMerge.exe connected to a malicious site to download the enc.exe encryptor payload.T1135 · Network Share DiscoveryThe article says the executed encryptor scans network shares.T1204.002 · Malicious FileThe delivery chain relied on a recipient opening downloaded files and executing the EXE from the ISO.T1486 · Data Encrypted for ImpactThe encryptor encrypts gathered data, leaving victim files with the .nZASJgT extension.T1562.001 · Disable or Modify ToolsThe article says the executed encryptor disables security processes.T1566.001 · Spearphishing AttachmentA payment-plan-themed phishing email carried the malicious PDF attachment.
Threat Actors
Malware
Black Lockescalating threats to the global digital economy. Global Group is a rebranding of the legacy Black Lock and Mamona ransomware families by inheriting an established backend infrastructure, reusing core codeGlobal Ransomwarepre-compromised corporate credentials, allowing their affiliates to bypass perimeter defenses. Global Ransomware utilizes double extortion and threats of public data leaks as part of their aggressive negotiationMamonathreats to the global digital economy. Global Group is a rebranding of the legacy Black Lock and Mamona ransomware families by inheriting an established backend infrastructure, reusing core code artifacts, and