Global Group Ransomware‑as‑Service Uses Phishing‑Delivered PDFs to Deploy Double‑Extortion Ransomware
What Happened – The Global Group ransomware‑as‑service (RaaS) operates a “payment‑plan” phishing campaign. Recipients receive a PDF that masquerades as a payment‑plan proposal; the PDF contains a “Download” button that leads to a malicious ISO. The ISO drops a disguised executable (Preview‑9dc7.exe) which launches a legitimate WinMerge process to fetch the encryptor payload. The ransomware encrypts data and the operators demand cryptocurrency while threatening public data release (double extortion).
Why It Matters for Trust & Control Assurance
- Phishing‑based initial access tests the effectiveness of your security awareness program and the controls around email attachment handling.
- The use of stolen credentials from Initial Access Brokers highlights the need for continuous credential‑risk monitoring and privileged‑access hygiene.
- Double‑extortion amplifies the impact of a breach, making incident‑response evidence (forensics, containment, communication) a critical component of a defensible audit trail.
Who Is Affected – Large‑scale enterprises across all verticals (finance, manufacturing, technology, healthcare, etc.) that rely on email for business communications.
Recommended Actions
- Validate that security‑awareness training includes simulated “payment‑plan” phishing scenarios and tracks click‑through rates.
- Deploy automated attachment sandboxing and block execution of unsigned binaries launched from legitimate tools (e.g., WinMerge).
- Ensure incident‑response playbooks cover ransomware containment, decryption‑key negotiation, and data‑leak‑notification procedures.
Technical Notes
- Delivery vector: phishing email with malicious PDF → ISO → executable → WinMerge loader → encryptor download from
globalsupportupdate.top. - No specific CVE; the attack leverages social engineering and trusted‑software masquerading.
- Ransom demands are paid in cryptocurrency; threat actors threaten public data release (double extortion).
Source: Cofense Intelligence – From Payment Plan to Ransomware