Ransomware Group intelligence
Global
ActiveTrack Global with 40 published victims and 5 known leak locations in a single intelligence view.
Overview
Global is tracked by Breach House as a ransomware group with 40 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 5 | Onion service | Up checked 59m ago | globalrbweyhxxa5b65bjjsm5bfuqfs5ydizefupqcminoedzn6o2sqd.onion |
| Leak location 4 | Onion service | Up checked 59m ago | globaldonejcrwbe7ujwuzptsummx3rvba54wcjoxrjvqgo37y4aqwid.onion |
| Leak location 3 | Onion service | Up checked 59m ago | globalco44t2yl6ltgj74cwthr6b6olggl3srg7engqfhx72f6ni3cyd.onion |
| Leak location 1 | Onion service | Down checked 59m ago | vg6xwkmfyirv3l6qtqus7jykcuvgx6imegb73hqny2avxccnmqt5m2id.onion |
| Leak location 2 | Onion service | Down checked 59m ago | gdbkvfe6g3whrzkdlbytksygk45zwgmnzh5i2xmqyo3mrpipysjagqyd.onion |
Top Activity Sectors (11)
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Global, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: global executes malicious commands via PowerShell scripts injected into legitimate processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: global modifies the Windows Registry Run keys to establish persistence across reboots.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: global disables antivirus tools by terminating security processes and modifying Windows Defender settings.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: global deletes Volume Shadow Copies and backup directories via vssadmin and native file deletion commands.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: global performs remote system discovery using native API calls to map victim infrastructure before deployment.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: global scans network shares using built-in Windows tools to identify unpatched systems for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: global exploits SMB/Windows Admin Shares to propagate laterally across networked servers in manufacturing environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: global exfiltrates stolen data via encrypted channels before initiating full system encryption.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: global encrypts victim files using a custom ransomware payload targeting critical healthcare and marketing data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README_Global.txt
GLOBAL Your network has been encrypted. All of your important files — documents, databases, backups, and configurations are now inaccessible. They have been locked using military-grade encryption. Only GLOBAL holds the decryption keys. What happened? ------------------------- We have gained full access to your internal network. During this time, sensitive data was exfiltrated and your systems were encrypted. Your business operations, internal communications, and customer data are at risk. What comes next? ------------------------- To restore access: 1. Download the Tor Browser (https://www.torproject.org/) 2. Visit our secure portal: gdbkvfe6g3whrzkdlbytksygk45zwgmnzh5i2xmqyo3mrpipysjagqyd.onion/chat/[snip] 3. Enter your unique ID: [snip] 4. Follow the instructions to begin negotiations. You may submit one small file (<1MB, non-sensitive) for free decryption as proof we hold the keys. We will also send you a file-listing to prove to you that we have stolen your data. Failure to engage within 3 days will result in: - Public release of your internal documents - Irreversible loss of your encrypted data - Escalation of your case to a wider leak network There is no other way. Do not waste time with third-party tools or law enforcement. You will only make things worse. This is not personal. Just business. Data Leak Site - http://vg6xwkmfyirv3l6qtqus7jykcuvgx6imegb73hqny2avxccnmqt5m2id.onion/ **GLOBAL operates globally.**
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (40)
Search, filter and paginate the victim timeline for Global. Showing 1–40 of 40.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Vigilia id32237 View details | Uruguay | Services | — | |
|
vigilia.com.uy operates within the Services sector and is situated in Uruguay. The entity functions as an online presence associated with service delivery and business activities in the region. Within the threat-intelligence index, vigilia.com.uy is formally listed as a ransomware victim, with the associated threat actor and source designated as global. This classification reflects the entity's documented relationship to ransomware activity under a broad, global attribution framework. The catalog entry provides neutral context for researchers and security professionals monitoring cyber incidents across sectors and geographies. |
|||||
| Ransomware | Vigilia id32237 View details | Uruguay | Services | — | |
|
VIGILIA is a company that provides support and care services for people. It offers assistance in medical facilities, home care, ambulance transportation, and related administrative support. The company also provides insurance policies and helps coordinate medical consultations and tests. |
|||||
| Ransomware | Hangzhou Qihan Biotech Co., Ltd. id32238 View details | China | Healthcare / Pharma | — | |
|
www.qihanbio.com operates within the Healthcare and Pharma sector and is headquartered in China. The entity provides bio-technology and pharmaceutical-related services, aligning with critical infrastructure sectors frequently targeted by cyber threats. Within the threat-intelligence index, www.qihanbio.com is formally categorized as a ransomware victim. The association with a global threat actor profile indicates the incident falls under international cyber threat analysis frameworks. This listing serves as a reference point for security professionals monitoring healthcare sector vulnerabilities and ransomware activity across geopolitical boundaries. |
|||||
| Ransomware | Hangzhou Qihan Biotech Co., Ltd. id32238 View details | China | Healthcare / Pharma | — | |
|
Qihan Biotech is a Hangzhou‑based biotech company specializing in gene editing and cell/organ therapies. It develops immune‑privileged cells and xenogeneic organs to treat cancer and organ failure. The company aims to make these therapies accessible worldwide. |
|||||
| Ransomware | Shanghai Tunnel Engineering Co Ltd id32239 View details | Singapore | IT | — | |
|
www.stecs.com.sg is an entity operating within the IT sector located in Singapore. The domain represents a company whose cybersecurity posture has been documented within a threat-intelligence index. This listing type identifies it as a ransomware victim, with the associated threat actor or source categorized broadly as global. The entry provides context for security professionals analyzing ransomware incidents across regional sectors and threat actor distributions. It neutrally records the association without disclosing unverified incident details. www.stecs.com.sg was listed as a ransomware victim associated with global. |
|||||
| Ransomware | Shanghai Tunnel Engineering Co Ltd id32239 View details | Singapore | IT | — | |
|
STECS is a leading civil engineering and construction company in Singapore, specializing in rail transit and underground projects. It has completed over 30 major projects for key clients like the Land Transport Authority and Public Utilities Board. The company prioritizes safety, environmental responsibility, and improving urban infrastructure in Southeast Asia. |
|||||
| Ransomware | Atcomm id32240 View details | China | Telecommunications | — | |
|
www.atcomm.cn operates within the telecommunications sector and is based in China. The entity represents a telecommunications organization whose infrastructure and services may be relevant to threat-intelligence analysis covering cyber incidents. According to the threat-intelligence index catalog, www.atcomm.cn is formally listed as a ransomware victim, with the associated threat actor or source identified as global. This listing reflects the entity's inclusion in ransomware victim records tied to broad global threat activity without disclosing specific incident details. The description maintains neutrality regarding confirmed breach specifics, operational impact, or unverified claims. |
|||||
| Ransomware | Atcomm id32240 View details | China | Telecommunications | — | |
|
@comm is a Shanghai‑based agency specializing in PR, digital marketing, and human‑AI collaboration. It leverages data and AI to help brands grow. The company operates from Room 2103, SK Building, in Pudong New Area. |
|||||
| Ransomware | awmedicalvillage.org id21872 View details | Lebanon | Healthcare / Pharma | — | |
|
AW Medical Village A lot of private information about patients. Diagnoses, addresses, phone numbers. Also insurance policy numbers and much more. |
|||||
| Ransomware | hmsaojose.com id21868 View details | Brazil | Healthcare / Pharma | — | |
|
Hospital Maternidade São José 1TB of private patient information. Personal details and more. |
|||||
| Ransomware | RUKU Tore - Türen id21448 View details | Germany | Hospitality / Food & Beverage / Tourism | — | |
|
RUKU Tore + Türen GmbH Ein junges, modernes Unternehmen mit langer Tradition Unser Name RUKU steht seit über 160 Jahren für höchste Qualität und Erfahrung in der Holzverarbeitung. Gemeinsam mit starken Partnern im In- und Ausland arbeiten wir an individuellen Lösungen für Sie. Das Ergebnis sind unsere einmaligen Produkte in handwerklicher Perfektion und unverwechselbarem Design. |
|||||
| Ransomware | Albavision.tv id21406 View details | Guatemala | Communication / Marketing | — | |
|
Albavisión is a major Latin American media company founded by Remigio Ángel González. Headquartered in Miami, it owns numerous TV and radio stations across Latin America. The company is known for acquiring struggling media outlets and revitalizing them with popular programming like telenovelas and U.S. films. === 400GB stolen. === |
|||||
| Ransomware | CONTRAQI id21381 View details | Mexico | Other | — | |
|
Unknown |
|||||
| Ransomware | Cyme Servicios Médicos id21380 View details | Mexico | Healthcare / Pharma | — | |
|
CYM Servicios Médicos - a Mexican‑based medical services clinic, offering general and specialist consultations, diagnostic services, and appointment-based care. It's active on Facebook and serves local communities with accessible healthcare services |
|||||
| Ransomware | Dithelm Travel Group id21379 View details | Thailand | Transportation / Travel / Logistics | — | |
|
The travel agency formerly known as Diethelm Travel, now operating as DTH Travel, is a destination management company (DMC) based in Asia with multiple offices across the continent. They specialize in tailor-made, responsible and authentic travel experiences, covering holiday packages, excursions, MICE and more, with a boutique, locally grounded service approach |
|||||
| Ransomware | Geomaticks Grecia id21378 View details | Greece | Services | — | |
|
Geomatics (also stylized Geomaticks) is a Greek company headquartered in Athens with over 20 years of experience in geoinformation technologies. They offer aerial surveying, photogrammetric mapping, cadastral surveying, orthophotomaps, LiDAR, GIS, and geographic data services throughout Greece and the broader Balkan, Middle East, and North Africa regions |
|||||
| Ransomware | Medical Village LIV id21377 View details | Healthcare / Pharma | — | ||
|
a healthcare facility offering a range of aesthetic and wellness treatments, such as facial procedures, microneedling, PRP, laser therapies, injectables, and more, focused on enhancing skin health and beauty through medical spa services |
|||||
| Ransomware | MukundRhotindian id21376 View details | Other | — | ||
|
Unknown |
|||||
| Ransomware | Rete Toscana Classica id21375 View details | Italy | Communication / Marketing | — | |
|
Rete Toscana Classica (RTC) is an Italian classical music radio station broadcasting 24/7 across Tuscany (Florence, Prato, Pisa, Livorno) via FM (93.3 / 93.1 MHz), DAB+, digital terrestrial TV, and worldwide online streaming |
|||||
| Ransomware | RTE id21374 View details | Ireland | Other | — | |
|
unknown |
|||||
| Ransomware | moelco.es id21364 View details | Spain | Manufacturing / Engineering | — | |
|
A Spanish industrial group focused on vacuum cooling systems for the agri-food sector, offering manufacturing, rental, and maintenance services to extend the freshness and shelf life of perishable produce. |
|||||
| Ransomware | lafavoritaservice.it id21363 View details | Italy | Manufacturing / Engineering | — | |
|
An Italian company specializing in maintenance, optimization, and eco-efficient upgrades of kilns and dryers for the ceramic tile industry, helping reduce energy consumption and production costs. |
|||||
| Ransomware | loraincountyauditor.gov id21141 View details | United States | Finance / Legal / Insurance | — | |
|
Lots of private information. Bank accounts and more. |
|||||
| Ransomware | Emphail.com id21078 View details | Other | — | ||
|
Unknown |
|||||
| Ransomware | entab.se id20898 View details | Sweden | Other | — | |
|
ENT Energiteknik AB is a company that operates in the Cultural & Informational Centers industry. The company is headquartered in Stockholm, Sweden. |
|||||
| Ransomware | Rosewood Farm id20592 View details | United States | Agriculture / Food | — | |
|
Rosewood Farm, located in Sugar Grove, Illinois, was established in 2019 by Julie, who is dedicated to reconnecting culinary practices with agricultural roots. Spanning approximately 6 acres, the farm specializes in naturally grown vegetables and vibrant flowers, focusing on sustainable farming practices. Rosewood Farm aims to promote farm-fresh goodness and community involvement, providing updates on events through their email list. |
|||||
| Ransomware | Morpeth Pharmacy id20591 View details | Australia | Healthcare / Pharma | — | |
|
Morpeth Pharmacy, officially known as Wellway Pharmacy Limited, is located at The Surgery, Wellway, Morpeth, Northumberland. Established on February 9, 1995, it operates as a private limited company. The pharmacy provides a range of healthcare services, including prescription dispensing, health consultations, and various over-the-counter medications. |
|||||
| Ransomware | Letry id20590 View details | Belgium | Communication / Marketing | — | |
|
Letry, based in Céroux, Belgium, operates as a garden center and nursery, offering a wide range of gardening products and services. The company specializes in garden planning, workshops, and training sessions aimed at enhancing gardening skills and knowledge. With a commitment to promoting gardening as a rewarding activity, Letry provides resources and support for both novice and experienced gardeners. |
|||||
| Ransomware | Skyline Dubuque id20589 View details | United States | Services | — | |
|
Skyline Dubuque, also known as Skyline Salt Solutions, is a family-owned business based in Dubuque, Iowa, specializing in snow removal and salt distribution. Founded by Mark Arthofer, the company emphasizes community involvement and a strong commitment to service excellence. Skyline offers a range of products and services related to snow management, including the patented Sky-Link Mix Master, which treats bulk road salt for improved effectiveness. |
|||||
| Ransomware | Fenol Kimya id20588 View details | Türkiye | Communication / Marketing | — | |
|
With our 20 years of knowledge and expertise; We promise not only a quality product, but more.. We offer our partners not only our products, but also services, on-site technical analysis of machines and formulations, sustainability development, workforce evaluations and R&D solutions. https://fenol.com.tr |
|||||
| Ransomware | Capitol Taxes id20587 View details | Services | — | ||
|
Established since 2014, Financial Services, Business Tax Preparation, Nationwide Services, Articles of incorporation. Voted #1 for most recommended Tax Services company by Local Chamber of Commerce |
|||||
| Ransomware | https://www.personalservice.com.br/ id20526 View details | Brazil | Communication / Marketing | ||
|
ERSONAL SERVICE is one of the leading service providers in Brazil, operating in the areas of Facilities, Business Process Outsourcing (BPO) solutions that combine Human Resources with processes and technology, and Technical Services for dealerships. Founded 21 years ago, the company is now present in 11 states across the country, with 12,000 employees and around 160 clients in sectors such as industries, shopping malls, corporate headquarters, hospitals, commercial and residential condominiums, among others |
|||||
| Ransomware | Deakin Medical id20525 View details | Australia | Healthcare / Pharma | ||
|
Deakin Medical Centre is a family-centered medical practice dedicated to providing high-quality healthcare services to the community. Established in 1985, the center focuses on personalized care, ensuring that each patient receives tailored medical attention to meet their unique health needs. |
|||||
| Ransomware | ad-engineering.co.uk id20524 View details | United Kingdom | Manufacturing / Engineering | ||
|
AD Engineering is a leading provider of innovative solutions for the packaging industry, specializing in Vertical Fill Form & Seal (VFFS) machinery. Founded over 14 years ago by Andy, a seasoned service engineer with extensive experience in the food sector, the company is dedicated to delivering high-quality, reliable, and cost-effective services to its clients. |
|||||
| Ransomware | Ascot Vale Health Group id20523 View details | Australia | Healthcare / Pharma | ||
|
Ascot Vale Health Group is a comprehensive healthcare provider located in Ascot Vale, Victoria, Australia. The organization is dedicated to delivering high-quality medical services and preventive care to the community, focusing on the holistic health of its patients. |
|||||
| Ransomware | TC Wilson id20498 View details | United States | Communication / Marketing | — | |
|
For nearly 100 years, Thomas C. Wilson – known as TC Wilson – has taken pride in crafting the finest products for tube cleaning, tube expanding, boiler and heat exchanger maintenance. Our knowledgeable staff understands the industry, and knows how to help you find the right equipment for your application and your budget. |
|||||
| Ransomware | LS Proline id20464 View details | Denmark | Communication / Marketing | — | |
|
L&S Proline is a Texas-based company providing turnkey equipment and fabrication solutions for the oil and gas industry, including flow measurement systems, custom enclosures, and structural supports—all built in-house for quality and reliability. |
|||||
| Ransomware | all-nations-health-center id20446 View details | United States | Healthcare / Pharma | — | |
|
all-nations-health-center |
|||||
| Ransomware | Epworth-Hospital id20433 View details | Australia | Healthcare / Pharma | — | |
|
Epworth HealthCare is a leading not-for-profit private hospital group in Victoria, Australia, known for high-quality medical, surgical, and rehabilitation services. Founded in 1920, it operates major hospitals across Melbourne and Geelong. |
|||||
| Ransomware | www.motorworldarc.co.uk id20432 View details | United Kingdom | Services | — | |
|
Motor World ARC is a UK-based company specializing in vehicle repairs and automotive services, offering expert solutions for a range of car-related needs. They provide high-quality accident repair, bodywork restoration, and mechanical services, with a commitment to customer satisfaction and precision. |
|||||