Phorpiex Phishing Delivers Low-Noise Global Group Ransomware
ID: a6d64b74-9bb7-5c37-bdf8-69913047d8e6
STIX ID: report--a6d64b74-9bb7-5c37-bdf8-69913047d8e6
Feed Name: Infosecurity Magazine (News)
Threat Score
A widespread phishing campaign uses deceptive Windows Shortcut (.lnk) attachments named like documents to launch cmd.exe and PowerShell, downloading a Phorpiex-associated payload that ultimately deploys Global Group ransomware; the ransomware operates offline, encrypts files with ChaCha20-Poly1305 (appending .Reco), drops README.Reco.txt, replaces desktop wallpaper, deletes shadow copies, and self-deletes, complicating detection and recovery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
