HackRead

Global Group Ransomware Abuses WinMerge to Deploy Encryptor


A Ransomware-as-a-Service (RaaS) operation known as Global Group is targeting large enterprises with phishing emails that deliver a file-encrypting payload.

Research shared with Hackread.com by the Cofense Phishing Defense Center (PDC) shows attackers using a fake payment plan, a malicious ISO file and the legitimate WinMerge application during the infection chain.

Cofense describes Global Group as “a rebranding of the legacy Black Lock and Mamona ransomware families,” with the operation reusing existing infrastructure and code.

Phishing Chain Delivers the Encryptor

The attack starts with an email posing as a “Suggested Payment Plan” and sent from a generic Hotmail address. Its PDF attachment, document_989399.pdf, contains a “Download” button. Clicking it sends the victim to driverupdate.sbs, which prompts them to save an ISO file.

The fake payment-plan document used to direct victims to the malicious ISO download. (Credit: Cofense)

The Preview-9dc7.iso file contains Preview-9dc7.exe and a shortcut named Preview-9dc7.pdf.lnk. When the executable runs, it launches WinMerge.exe, a legitimate file-comparison application.

Cofense observed WinMerge connecting to globalsupportupdate.top to retrieve enc.exe, the ransomware encryptor. Researchers also manually accessed the payload server during their analysis. It is worth noting that WinMerge itself was not compromised. The attackers abused the legitimate application as part of the ransomware delivery process.

The encryptor unpacks additional components into C:Python27.x86, scans local drives, network shares and databases, and disables security processes before encrypting files. The next step involves encrypted files receiving the nZASJgT extension. The malware changes the desktop wallpaper to display the ransom note and drops README.nZASJgT.txt with payment and file recovery instructions.

The infection chain uses a malicious ISO before WinMerge retrieves the Global Group ransomware encryptor. (Credit: Cofense)

Ransomware Made to Look Like a Business Service

According to Cofense’s blog post, the ransom note offers decryption keys, technical information about the attack, assistance with cyber insurance claims and reputation-management services. The operators present the extortion as a business transaction, offering additional services alongside the ransom demand.

Global Group’s ransom message presents payment, file recovery and other services to the victim. (Credit: Cofense)

The operation also uses double extortion, stealing sensitive information and threatening to publish it if the ransom is not paid. Cofense recommends that organizations search for the reported filenames, file extensions and network indicators to identify potential infections.

The phishing campaign is one part of a broader RaaS operation. Global Group also works with Initial Access Brokers (IABs), which sell access to already-compromised corporate networks, giving affiliates another route to deploy ransomware.





Source link