Cofense Details Global Group Ransomware Attack Chain and Indicators

· Original article ↗

Summary

Cofense describes a Global Group ransomware campaign delivered through a fake payment-plan email. The attack uses a PDF lure, ISO and executable files, then encrypts data and threatens victims with public leaks.

Key points

  • Cofense reports that Global Group operates a ransomware-as-a-service operation linked to the legacy Black Lock and Mamona ransomware families.
  • The campaign email posed as a suggested payment plan and included a PDF with a download lure leading to a malicious ISO file.
  • The ISO contained an executable and a shortcut; the executable launched legitimate WinMerge, which connected to a site hosting the encryptor.
  • The encryptor scans local drives, network shares, and databases, disables security processes, and encrypts data. Encrypted files use the .nZASJgT extension.
  • The ransom note offers decryption and other purported services while threatening to publish extracted data if victims do not pay.
  • Cofense says the group works with initial access brokers that supply pre-compromised corporate credentials.
  • The report provides file hashes and URLs/IP addresses associated with the delivery and command-and-control infrastructure.

Article Details

Attack Vectors
  • A payment-plan-themed email delivered a malicious PDF attachment.
  • The PDF's Download button redirected recipients to a malicious file-download site, where they were prompted to save an ISO file.
  • The ISO contained an executable and a shortcut pointing to that executable. Running it spawned WinMerge.exe, which connected to a site hosting the encryptor payload.
  • The article says Global Group partners with Initial Access Brokers to purchase pre-compromised corporate credentials for its affiliates.
Defensive Notes
  • Cofense recommends proactively hunting for possible entry points in organizational security infrastructure.
  • Cofense cautions that its observations about circumventing endpoint protections reflect specific configurations at a point in time; updates or different configurations may stop similar threats.

Indicators of compromise

TypeIndicatorContext
IPV4104[.]21[.]92[.]70IP listed with an observed command-and-control URL.
IPV4172[.]67[.]175[.]15IP listed with the observed payload URL.
IPV4172[.]67[.]188[.]157IP listed with an observed command-and-control URL.
MD51e2c4cd35987ee217994149675784f9fMD5 of the malicious Preview-9dc7.pdf.lnk shortcut.
MD520417846820741fa84c4571affb40e9cMD5 of ptc1591.exe, listed among discovered malicious files.
MD52abd445d3d60fd207b2c62bb0da3a42bMD5 of the malicious document_989399.pdf attachment.
MD55dee17e91f79be742881324bcdf139a5MD5 of the malicious Preview-9dc7.exe file.
MD59db4b94589728b68d51bf83a90211cfeMD5 of the malicious Preview-9dc7.iso file.
SHA25600f70ae018e71f51060346aaa101209c24e34697bbfafec6b3612db8d8127cb2SHA-256 of the malicious Preview-9dc7.iso file.
SHA25664388cdbfe48dcff05eaa455892bcb3bfcaa3d43559eb7c65f6ac772810be61eSHA-256 of the malicious Preview-9dc7.pdf.lnk shortcut.
SHA256997cf28771fde81c6bfc067eed1f19d0ad3554342d63d9469d3adcdc1ca0ff31SHA-256 of the malicious Preview-9dc7.exe file.
SHA2569fb468a79f88d9a250180749bfae97d4f310c8510f1f98cae359d95c2a62b4afSHA-256 of ptc1591.exe, listed among discovered malicious files.
SHA256d5004e079cb46db15a7d0b7ecebfa47bb8a1bc19e25749849a017b2a36705260SHA-256 of the malicious document_989399.pdf attachment.
URLhxxps[:]//driverupdate[.]sbs/access[.]phpMalicious file-download page reached through the PDF's Download button.
URLhxxps[:]//driverupdate[.]sbs/access[.]php?t=notes-a408dfObserved malicious payload URL.
URLhxxps[:]//globalsupportupdate[.]topMalicious site contacted by WinMerge.exe and described as hosting the encryptor payload.
URLhxxps[:]//globalsupportupdate[.]top/enc[.]exeObserved command-and-control URL for the encryptor payload.
URLhxxps[:]//playmounthdom[.]top/Observed command-and-control URL.

MITRE ATT&CK

Threat Actors

Malware

Products

Related Articles