$ techbeacon▋
Ransomware

Global Group Ransomware Campaign Leverages WinMerge and Fake Payment Emails to Target Enterprises

Global Group Ransomware Campaign Leverages WinMerge and Fake Payment Emails to Target Enterprises

Security researchers at Cofense have detailed a new tactic employed by the cyber‑crime outfit known as Global Group, which blends payment‑related phishing lures with malicious ISO images and the open‑source file‑comparison tool WinMerge to deliver ransomware payloads against large corporations.

The campaign begins with emails that mimic invoices, payment confirmations or other finance‑related correspondence, prompting recipients to download an attached ISO file. Once mounted, the ISO contains a disguised executable that launches WinMerge, a legitimate utility normally used to compare and merge text files. Global Group has modified the program so that, during its normal operation, it silently copies a ransomware encryptor onto the victim’s system and initiates encryption without the user’s awareness.

According to Cofense, the use of WinMerge is a calculated move to evade detection. Because the software is widely trusted and often whitelisted by enterprise security policies, its presence on a network does not raise immediate alarms. By piggybacking the ransomware on a familiar tool, the attackers gain a window of opportunity to encrypt files before security teams can respond.

The focus on payment‑themed phishing is also strategic. Large enterprises routinely process high‑value invoices and settlements, making finance staff a prime target for social engineering. The deceptive emails are crafted to appear as routine communications from known vendors, complete with authentic‑looking branding and reference numbers, increasing the likelihood that recipients will follow the attachment link.

Cofense’s analysis highlights that the ransomware payloads deployed by Global Group are designed for extortion rather than mere data destruction. After encryption, victims receive a demand for payment, often in cryptocurrency, with threats to publish stolen data or continue the attack if the ransom is not met. This double‑extortion model aligns with trends observed in other high‑profile ransomware operations.

While the exact financial impact of the campaign remains under investigation, the targeting of “large enterprises” suggests potential losses in the millions of dollars, both from downtime and ransom payments. The findings underscore the importance of robust email security, strict verification of invoice communications, and the need to scrutinize any unexpected use of legitimate utilities on corporate networks.

Industry experts recommend that organizations implement multi‑layered defenses, including advanced phishing detection, sandboxing of all executable files from external sources, and application control policies that restrict the execution of uncommon software like WinMerge in privileged contexts. Regular employee training on recognizing finance‑related phishing attempts remains a critical line of defense.

As Global Group continues to refine its methods, security teams are urged to share indicators of compromise and collaborate across sectors to disrupt the ransomware supply chain. Ongoing monitoring of threat intelligence feeds and prompt patching of vulnerabilities in file‑handling utilities will be essential to mitigate future iterations of this campaign.

Source: Hackread
Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related