Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools

Since its inception in early June 2025, the new ransomware-as-a-service (RaaS) operation known as GLOBAL GROUP has targeted a variety of industries in Australia, Brazil, Europe, and the US, according to cybersecurity researchers.

According to Arda Büyükkaya, a researcher at EclecticIQ, GLOBAL GROUP was “promoted on the Ramp4u forum by the threat actor known as ‘$$$,'” “The same actor controls the BlackLock RaaS and previously managed Mamona ransomware operations.”

After the DragonForce ransomware gang vandalized BlackLock’s data leak website in March, it is thought that GLOBAL GROUP is a rebranding of BlackLock. It’s important to note that BlackLock is merely a rebranding of Eldorado, another RaaS scheme.

It has been discovered that the profit-driven gang primarily relies on initial access brokers (IABs) to spread the ransomware by using them to gain access to Cisco’s vulnerable edge appliances read more about Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *