Global
Ransomware Group Profile
Overview
GLOBAL GROUP is a ransomware-as-a-service operation that emerged in June 2025, reportedly launched by a known Russian-speaking threat actor, featuring AI-driven ransom negotiation and a mobile control panel for affiliates, targeting healthcare, oil and gas, industrial engineering, and automotive sectors.
Dark Web Infrastructure (7)
vg6xwkmfyirv3l6qtqus7jykcuvgx6imegb73hqny2avxccnmqt5m2id.onion
panelqbinglxczi2gqkwderfvgq6bcv5cbjwxrksjtvr5xv7ozh5wqad.onion
gdbkvfe6g3whrzkdlbytksygk45zwgmnzh5i2xmqyo3mrpipysjagqyd.onion
7bmz2tc4p2jk23dcyehg37cd7veflk3fyhxrnbxz75vvno2azfy6qayd.onion
globalrbweyhxxa5b65bjjsm5bfuqfs5ydizefupqcminoedzn6o2sqd.onion
globaldonejcrwbe7ujwuzptsummx3rvba54wcjoxrjvqgo37y4aqwid.onion
globalco44t2yl6ltgj74cwthr6b6olggl3srg7engqfhx72f6ni3cyd.onion
Activity Timeline
First Seen2025
Last Seen2025
Leak Sites7
Quick Actions