logo

Hackers Deliver Global Group Ransomware Offline via Phishing Emails

ID: 2fb583f4-6be8-5e2c-a45a-526330823251

STIX ID: report--2fb583f4-6be8-5e2c-a45a-526330823251

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-02-09

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Researchers at Forcepoint X‑Labs uncovered a global phishing campaign (active 2024–2025) where Phorpiex-distributed .lnk shortcuts drop Global Group ransomware. The malware leverages Living-off-the-Land (PowerShell/CMD), generates encryption keys locally (offline 'mute' mode) using ChaCha20-Poly1305, removes evidence (self-delete, VSS deletion), and appends a .Reco extension to encrypted files; common IOCs include Document.doc.lnk, windrv.exe, a 127.0.0.7 ping timer, and the ransom note wallpaper.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.