Skip to main content

Operator dossier

global is a ransomware operator currently active on public leak sites. Darkfield has indexed 39 public victims claimed by this operator between June 4, 2025 and September 12, 2026. The "global" ransomware group is a relatively new threat actor that emerged in June 2025, operating with primarily financial motivations based on their ransomware deployment activities. Due to the group's recent emergence and limited public documentation from major cybersecurity organizations, specific details about their country of origin, affiliations, and operational structure remain unclear, though their targeting patterns suggest broad international scope. Based on available data, the group has compromised 32 known victims across multiple countries including the United States, Australia, Brazil, Great Britain, and Mexico, with their attacks primarily focused on healthcare, manufacturing, technology, and public sector organizations. The group's attack methodology, encryption techniques, and specific tools remain undocumented in publicly available threat intelligence reports from established security research organizations. Given the limited timeframe since their first observed activity in June 2025, there are no widely reported major campaigns or high-profile incidents attributed to this group in public threat intelligence sources. The current operational status of the "global" ransomware group remains active based on their recent emergence, though comprehensive analysis is limited due to the lack of detailed public reporting from major cybersecurity firms and government agencies.

Most-targeted sectors

Most-affected countries

Recent disclosures by global

All 39 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for global

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status changes from active to dormant when no new disclosure appears for 60 days. Without a disclosure date, activity is unknown. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

global

39 victims indexed · first seen 1 year ago · last activity 4 days ago

39
Victims indexed
#133 of 399 tracked operators
1y 3m
Active period
Jun 2025 → Sep 2026
10
Countries hit
top US · 3

At a glance

Status
inactive
First seen
1 year ago
Last activity
4 days ago
Onion sites
1 known endpoint
Primary sector
Not Found · 13 hits

About

The "global" ransomware group is a relatively new threat actor that emerged in June 2025, operating with primarily financial motivations based on their ransomware deployment activities. Due to the group's recent emergence and limited public documentation from major cybersecurity organizations, specific details about their country of origin, affiliations, and operational structure remain unclear, though their targeting patterns suggest broad international scope. Based on available data, the group has compromised 32 known victims across multiple countries including the United States, Australia, Brazil, Great Britain, and Mexico, with their attacks primarily focused on healthcare, manufacturing, technology, and public sector organizations. The group's attack methodology, encryption techniques, and specific tools remain undocumented in publicly available threat intelligence reports from established security research organizations. Given the limited timeframe since their first observed activity in June 2025, there are no widely reported major campaigns or high-profile incidents attributed to this group in public threat intelligence sources. The current operational status of the "global" ransomware group remains active based on their recent emergence, though comprehensive analysis is limited due to the lack of detailed public reporting from major cybersecurity firms and government agencies.

References

7 links

External sources curated by the MISP threat-intel community.

Timeline

3 months
2025-06-01T00:00:00+00:00 · 162025-07-01T00:00:00+00:00 · 142025-08-01T00:00:00+00:00 · 2
2025-06-01T00:00:00+00:002025-08-01T00:00:00+00:00

Top countries

🇺🇸 United States
3
🇦🇺 Australia
3
🇧🇷 Brazil
2
🇬🇧 United Kingdom
2
🇲🇽 Mexico
2
🇪🇸 Spain
1
🇹🇭 Thailand
1
🇮🇹 Italy
1

Top sectors

Healthcare
8
Manufacturing
3
Technology
2
Public Sector
1
Business Services
1
Telecommunication
1
Transportation/Logistics
1
Financial Services
1

MITRE ATT&CK

3 techniques · 3 tactics

Tactics

Initial AccessExecutionImpact

Techniques

  • T1566Phishing
  • T1059Command and Scripting Interpreter
  • T1486Data Encrypted for Impact

Recent victims

  • Loading recent victims

Onion infrastructure

1 known
  • http://vg6xwkmfyirv3l6qtqus7jykcuvgx6imegb73hqny2avxccnmqt5m2id.onion

Source

Updated 4 days ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time global posts a victim.

Add global to your watchlist — Pro pings you within 5 minutes of any new global leak-site post, Telegram callout, or affiliate-rebrand inference.