Skip to main content

Operator dossier

global is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 32 public victims claimed by this operator between June 4, 2025 and August 20, 2025. The "global" ransomware group is a relatively new threat actor that emerged in June 2025, operating with primarily financial motivations based on their ransomware deployment activities. Due to the group's recent emergence and limited public documentation from major cybersecurity organizations, specific details about their country of origin, affiliations, and operational structure remain unclear, though their targeting patterns suggest broad international scope. Based on available data, the group has compromised 32 known victims across multiple countries including the United States, Australia, Brazil, Great Britain, and Mexico, with their attacks primarily focused on healthcare, manufacturing, technology, and public sector organizations. The group's attack methodology, encryption techniques, and specific tools remain undocumented in publicly available threat intelligence reports from established security research organizations. Given the limited timeframe since their first observed activity in June 2025, there are no widely reported major campaigns or high-profile incidents attributed to this group in public threat intelligence sources. The current operational status of the "global" ransomware group remains active based on their recent emergence, though comprehensive analysis is limited due to the lack of detailed public reporting from major cybersecurity firms and government agencies.

Most-targeted sectors

Most-affected countries

Recent disclosures by global

All 32 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for global

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

global

32 victims indexed · first seen 1 year ago · last activity 11 months ago

32
Victims indexed
#140 of 370 tracked operators
2m
Active period
Jun 2025 → Aug 2025
10
Countries hit
top US · 3

At a glance

Status
inactive
First seen
1 year ago
Last activity
11 months ago
Onion sites
1 known endpoint
Primary sector
Not Found · 13 hits

About

The "global" ransomware group is a relatively new threat actor that emerged in June 2025, operating with primarily financial motivations based on their ransomware deployment activities. Due to the group's recent emergence and limited public documentation from major cybersecurity organizations, specific details about their country of origin, affiliations, and operational structure remain unclear, though their targeting patterns suggest broad international scope. Based on available data, the group has compromised 32 known victims across multiple countries including the United States, Australia, Brazil, Great Britain, and Mexico, with their attacks primarily focused on healthcare, manufacturing, technology, and public sector organizations. The group's attack methodology, encryption techniques, and specific tools remain undocumented in publicly available threat intelligence reports from established security research organizations. Given the limited timeframe since their first observed activity in June 2025, there are no widely reported major campaigns or high-profile incidents attributed to this group in public threat intelligence sources. The current operational status of the "global" ransomware group remains active based on their recent emergence, though comprehensive analysis is limited due to the lack of detailed public reporting from major cybersecurity firms and government agencies.

References

7 links

External sources curated by the MISP threat-intel community.

Timeline

3 months
2025-06-01T00:00:00+00:00 · 162025-07-01T00:00:00+00:00 · 142025-08-01T00:00:00+00:00 · 2
2025-06-01T00:00:00+00:002025-08-01T00:00:00+00:00

Top countries

🇺🇸 United States
3
🇦🇺 Australia
3
🇧🇷 Brazil
2
🇬🇧 United Kingdom
2
🇲🇽 Mexico
2
🇪🇸 Spain
1
🇹🇭 Thailand
1
🇮🇹 Italy
1

Top sectors

Healthcare
8
Manufacturing
3
Technology
2
Public Sector
1
Business Services
1
Telecommunication
1
Transportation/Logistics
1
Financial Services
1

MITRE ATT&CK

3 techniques · 3 tactics

Tactics

Initial AccessExecutionImpact

Techniques

  • T1566Phishing
  • T1059Command and Scripting Interpreter
  • T1486Data Encrypted for Impact

Recent victims

Loading…

Onion infrastructure

1 known
  • http://vg6xwkmfyirv3l6qtqus7jykcuvgx6imegb73hqny2avxccnmqt5m2id.onion

Source

Updated 11 months ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time global posts a victim.

Add global to your watchlist — Pro pings you within 5 minutes of any new global leak-site post, Telegram callout, or affiliate-rebrand inference.