GLOBAL GROUP
GLOBAL GROUP is a ransomware-as-a-service operation and apparent rebrand of the BlackLock operation, which was previously known as Eldorado or El Dorado. The content states the branding evolved from Eldorado on the Russian Anonymous Marketplace (RAMP) forum in March 2024, to BlackLock by late 2024, and then to GLOBAL GROUP around mid-2025. It is described as part of the Russian-speaking cybercriminal ransomware ecosystem rather than a nation-state actor, with no evidence of nation-state involvement. The group is associated with affiliate-based ransomware operations and recruitment activity on RAMP, where GLOBAL GROUP, Eldorado, and other major ransomware brands sought members, advertised variants, and shared operational intelligence. The operation is described as having offered affiliates revenue shares up to 85% and as providing a custom Go-based builder capable of generating Windows, Linux, and ESXi encryptors. The content links GLOBAL GROUP/BlackLock to campaigns involving social-engineering delivery, including a malicious LNK file disguised as FAKE_CAPTCHA that triggered hidden PowerShell or command-line execution and used living-off-the-land binaries to deploy a second-stage loader. Associated infrastructure included paksecurity[.]org and techoption[.]org. The loader was described as establishing persistence via scheduled tasks and beaconing to command-and-control infrastructure. The group’s ransomware capability is described as cross-platform and particularly relevant to VMware ESXi environments, with an attack playbook that included enumerating /vmfs/volumes/, killing running virtual machines with esxcli vm process kill, encrypting .vmdk and .vmx files, dropping ransom notes such as HOW_RETURN_YOUR_DATA.TXT, and deleting backups via vssadmin or WMI. The ransomware is described as using ChaCha20 or XChaCha20 for file encryption with RSA-OAEP for key wrapping. One report in the content describes GLOBAL GROUP ransomware as notable for carrying out activity locally, being compatible with air-gapped environments, and conducting no data exfiltration. Another report describes GLOBAL GROUP as operating a Tor-based negotiation portal where an AI chatbot interacts with victims, automates communications, and applies psychological pressure during negotiations. The content also notes victim claims by the group, including a July 2025 claim of stealing 400GB of data from Albavisión. Reported targeting in the content includes organizations in the United States and Europe across healthcare, manufacturing, education, government, and media sectors. Known aliases directly supported by the content are BlackLock, Eldorado, and El Dorado.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Media & Entertainment
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Tradecraft
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service operation focused on ESXi and broader hypervisor attacks, using phishing/LNK-based initial access, loaders, Active Directory compromise, lateral movement, and cross-platform encryptors to conduct recovery-denial extortion against organizations.
Ransomware crew delivered via phishing/LNK → PowerShell → Phorpiex dropper chain; notable for local-only activity (air-gapped compatible) and no data exfiltration.
GLOBAL Group is a ransomware group utilizing RAMP for collaboration, recruitment, and operational coordination.
Ransomware-as-a-service operation (possibly a Black Lock rebrand) using an AI chatbot in a Tor-based negotiation portal to automate victim communications, apply psychological pressure, and scale extortion operations.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.