Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Global Group Ransomware‑as‑Service Deploys Phishing PDFs for Double‑Extortion Attacks

The Global Group RaaS uses a payment‑plan phishing campaign to deliver ransomware that encrypts data and threatens public leaks. The tactic stresses the need for robust security‑awareness training, credential‑risk monitoring, and incident‑response evidence for audit readiness.

LiveThreat™ Intelligence · 📅 September 22, 2026· 📰 cofense.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
cofense.com

Global Group Ransomware‑as‑Service Uses Phishing‑Delivered PDFs to Deploy Double‑Extortion Ransomware

What Happened – The Global Group ransomware‑as‑service (RaaS) operates a “payment‑plan” phishing campaign. Recipients receive a PDF that masquerades as a payment‑plan proposal; the PDF contains a “Download” button that leads to a malicious ISO. The ISO drops a disguised executable (Preview‑9dc7.exe) which launches a legitimate WinMerge process to fetch the encryptor payload. The ransomware encrypts data and the operators demand cryptocurrency while threatening public data release (double extortion).

Why It Matters for Trust & Control Assurance

  • Phishing‑based initial access tests the effectiveness of your security awareness program and the controls around email attachment handling.
  • The use of stolen credentials from Initial Access Brokers highlights the need for continuous credential‑risk monitoring and privileged‑access hygiene.
  • Double‑extortion amplifies the impact of a breach, making incident‑response evidence (forensics, containment, communication) a critical component of a defensible audit trail.

Who Is Affected – Large‑scale enterprises across all verticals (finance, manufacturing, technology, healthcare, etc.) that rely on email for business communications.

Recommended Actions

  • Validate that security‑awareness training includes simulated “payment‑plan” phishing scenarios and tracks click‑through rates.
  • Deploy automated attachment sandboxing and block execution of unsigned binaries launched from legitimate tools (e.g., WinMerge).
  • Ensure incident‑response playbooks cover ransomware containment, decryption‑key negotiation, and data‑leak‑notification procedures.

Technical Notes

  • Delivery vector: phishing email with malicious PDF → ISO → executable → WinMerge loader → encryptor download from globalsupportupdate.top.
  • No specific CVE; the attack leverages social engineering and trusted‑software masquerading.
  • Ransom demands are paid in cryptocurrency; threat actors threaten public data release (double extortion).

Source: Cofense Intelligence – From Payment Plan to Ransomware

📰 Original Source
https://cofense.com/blog/from-payment-plan-to-ransomware-inside-a-global-group-attack ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →