Threat Group Profile
global
● Active — last 30 days
Victim claims
1
First seen
Aug 2026
Last activity
26 Aug 2026
Tracked since
Jun 2025
Group overview
GLOBAL GROUP is a ransomware-as-a-service operation that emerged in June 2025, reportedly launched by a known Russian-speaking threat actor, featuring AI-driven ransom negotiation and a mobile control panel for affiliates, targeting healthcare, oil and gas, industrial engineering, and automotive sectors.
Preferred targets
Technology · 1
Most targeted countries
CN · 1