logo

Phorpiex Phishing Delivers Low-Noise Global Group Ransomware

ID: a6d64b74-9bb7-5c37-bdf8-69913047d8e6

STIX ID: report--a6d64b74-9bb7-5c37-bdf8-69913047d8e6

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-02-10

Date Updated: 2026-04-22

...
...

A widespread phishing campaign uses deceptive Windows Shortcut (.lnk) attachments named like documents to launch cmd.exe and PowerShell, downloading a Phorpiex-associated payload that ultimately deploys Global Group ransomware; the ransomware operates offline, encrypts files with ChaCha20-Poly1305 (appending .Reco), drops README.Reco.txt, replaces desktop wallpaper, deletes shadow copies, and self-deletes, complicating detection and recovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.