HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

Global Group Ransomware‑as‑Service Deploys Phishing PDFs for Double‑Extortion Attacks

The Global Group RaaS uses a payment‑plan phishing campaign to deliver ransomware that encrypts data and threatens public leaks. The tactic stresses the need for robust security‑awareness training, credential‑risk monitoring, and incident‑response evidence for audit readiness.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 cofense.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
cofense.com

Global Group Ransomware‑as‑Service Uses Phishing‑Delivered PDFs to Deploy Double‑Extortion Ransomware

What Happened – The Global Group ransomware‑as‑service (RaaS) operates a “payment‑plan” phishing campaign. Recipients receive a PDF that masquerades as a payment‑plan proposal; the PDF contains a “Download” button that leads to a malicious ISO. The ISO drops a disguised executable (Preview‑9dc7.exe) which launches a legitimate WinMerge process to fetch the encryptor payload. The ransomware encrypts data and the operators demand cryptocurrency while threatening public data release (double extortion).

Why It Matters for Trust & Control Assurance

  • Phishing‑based initial access tests the effectiveness of your security awareness program and the controls around email attachment handling.
  • The use of stolen credentials from Initial Access Brokers highlights the need for continuous credential‑risk monitoring and privileged‑access hygiene.
  • Double‑extortion amplifies the impact of a breach, making incident‑response evidence (forensics, containment, communication) a critical component of a defensible audit trail.

Who Is Affected – Large‑scale enterprises across all verticals (finance, manufacturing, technology, healthcare, etc.) that rely on email for business communications.

Recommended Actions

  • Validate that security‑awareness training includes simulated “payment‑plan” phishing scenarios and tracks click‑through rates.
  • Deploy automated attachment sandboxing and block execution of unsigned binaries launched from legitimate tools (e.g., WinMerge).
  • Ensure incident‑response playbooks cover ransomware containment, decryption‑key negotiation, and data‑leak‑notification procedures.

Technical Notes

  • Delivery vector: phishing email with malicious PDF → ISO → executable → WinMerge loader → encryptor download from globalsupportupdate.top.
  • No specific CVE; the attack leverages social engineering and trusted‑software masquerading.
  • Ransom demands are paid in cryptocurrency; threat actors threaten public data release (double extortion).

Source: Cofense Intelligence – From Payment Plan to Ransomware

📰 Original Source
https://cofense.com/blog/from-payment-plan-to-ransomware-inside-a-global-group-attack

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →