Global Group Ransomware Leverages WinMerge and Malicious ISO Files to Deploy Encryptors
What Happened — Cofense researchers disclosed that the Global Group ransomware gang is using payment‑themed phishing emails, malicious ISO images and the legitimate file‑comparison tool WinMerge to deliver their encryptor payloads against large enterprises.
Why It Matters for Trust & Control Assurance
- The abuse of a trusted utility (WinMerge) illustrates the need for continuous execution‑control monitoring and evidence that only authorized binaries run in production.
- Detecting and documenting such “living‑off‑the‑land” techniques is a core scenario that a control‑assurance program must capture to provide a defensible audit trail.
Who Is Affected – Large enterprises across multiple sectors that allow the use of standard admin utilities on employee workstations.
Recommended Actions – Review and tighten application‑allowlist policies, enforce least‑privilege for tooling, implement continuous monitoring of legitimate software usage, and collect evidence for audit readiness. Source: HackRead
Technical Notes – Attack vector: payment‑themed phishing → malicious ISO → execution of WinMerge to launch ransomware encryptor. No specific CVE cited. Source: HackRead