LIVE
LATEST THREAT: Cl0p Goes Public: Windchill Campaign Victim List Tops 40, GE Quietly Disappears THREAT ALERT ACTIVE
Intelligence DB / Group Profile Global Group

Global Group: RaaS Operation Pairs AI-Driven Negotiation With a Mobile Affiliate Panel

Global Group, a ransomware-as-a-service brand assessed by researchers as a likely rebrand of Black Lock, has scaled rapidly since its mid-2025 launch on the strength of an 80/20 affiliate split, a mobile-friendly control panel, and an AI chatbot that runs ransom negotiations for non-English-speaking affiliates. A related leak site operating as Global Secret Group has separately claimed a disputed tally of over 202,000 victims.

By Ransomware Tracker ·
Global GroupGlobal Secret GroupGSGransomwareRaaSAI negotiationBlack Lockaffiliate recruitmentdouble extortion2026
Threat Level
8/10
Sectors Targeted
healthcare
manufacturing
financial services
professional services
construction
automotive
retail
transportation
Ransomware Family
Global Group

Overview

Global Group is a ransomware-as-a-service operation that surfaced in mid-2025 and has drawn renewed attention in 2026 for a feature set unusual even by the standards of an increasingly commoditized RaaS market: an AI-driven negotiation chatbot built into the affiliate panel, and a mobile-friendly control interface that lets affiliates manage active extortions from a phone. Researchers at EclecticIQ, who have tracked the brand’s infrastructure since launch, assess with medium confidence that Global Group represents a rebrand of the Black Lock RaaS operation, pointing to shared hosting on Russian VPS provider IpServer as supporting technical evidence.

A separately branded dedicated leak site calling itself Global Secret Group (GSG) has drawn additional coverage in recent weeks, claiming an eyebrow-raising total of more than 202,000 victims. Researchers tracking the site describe that figure as unverified and likely inflated — leak sites frequently pad victim counts to project scale — but note that confirmed, independently corroborated postings continue to accumulate on both properties, with victims identified in the United States, Europe, Canada, India, the United Arab Emirates, Cyprus, and Argentina. Because naming conventions in this segment are fluid and operators frequently rebrand or spin up parallel leak sites to diffuse takedown risk, defenders should treat “Global Group” and “Global Secret Group” as closely related — and possibly identical — infrastructure rather than fully separate threats.

AI-Powered Negotiation

The operation’s most distinctive claim is an automated negotiation system built into its victim-facing chat portal. According to reporting from EclecticIQ and multiple trade outlets that reviewed the panel, the AI component is designed primarily to assist affiliates who do not speak English fluently, generating negotiation responses and applying psychological pressure tactics during ransom discussions. The stated goal is to keep negotiations moving toward the seven-figure demands the group reportedly favors for larger targets, without requiring an affiliate to personally handle real-time back-and-forth with a victim’s incident response team or negotiator.

This is a meaningful operational shift. Ransom negotiation has traditionally been a labor-intensive, skill-dependent part of running an affiliate operation — a poorly handled negotiation can collapse a payment a well-run one would have closed. Automating even part of that process lowers the skill bar for affiliates and could let less experienced operators extract higher payments than they otherwise would, a trend worth watching across the RaaS market more broadly.

Mobile Affiliate Panel and Revenue Split

Global Group’s affiliate portal is reportedly mobile-compatible, letting operators monitor infections, generate builds, and manage negotiations from a phone rather than requiring a dedicated workstation. Combined with cross-platform locker builds, this lowers the operational overhead of running an affiliate campaign considerably.

The group advertises an affiliate revenue split of 80–85%, with operators retaining the remainder — at or above the high end of the industry-standard range, and reported as an explicit pitch to rebuild trust and expand the affiliate roster following the group’s earlier rebrand. Aggressive splits like this are a recurring recruitment tactic among newer or rebranded RaaS brands trying to pull affiliates from more established operations.

Initial Access and Targeting

Public reporting describes Global Group affiliates relying heavily on initial access brokers (IABs) to obtain footholds, with particular emphasis on exposed and vulnerable edge appliances from Fortinet, Palo Alto Networks, and Cisco. This mirrors the broader 2026 trend across the ransomware ecosystem, where perimeter VPN and firewall appliances remain among the most commonly exploited entry points because they are internet-facing, frequently unpatched, and provide direct network access once compromised.

Victims identified on the group’s leak sites span a broad range of sectors — healthcare, financial services, manufacturing, real estate, professional services, construction, retail, transportation, and technology — consistent with an opportunistic, IAB-fed targeting model rather than a sector-specific campaign. Confirmed postings include healthcare providers in the United States and Australia and an automotive services firm in the United Kingdom, among others tracked by open-source monitoring services.

Assessment

Global Group’s combination of a rebrand pedigree, an aggressive affiliate split, and genuinely novel tooling — the AI negotiation assistant in particular — positions it as one of the more operationally interesting RaaS entrants of 2026, even if its self-reported victim totals should be treated with skepticism. The EclecticIQ assessment linking the group to Black Lock is notable because rebrands of previously disrupted or fading operations often inherit an experienced affiliate base and existing tooling, letting the new brand scale faster than a genuinely new entrant could.

The unverified 202,000-victim claim attached to the Global Secret Group leak site is almost certainly not a literal count of successful ransomware intrusions; leak-site victim counters are marketing artifacts as much as they are threat intelligence, and researchers have flagged the figure explicitly as unconfirmed. Analysts should continue to rely on independently corroborated postings — cross-referenced against trackers like ransomware.live and RansomLook — rather than the group’s own claimed statistics when assessing scale.

Defensive Priorities

Given the group’s reported reliance on IAB-supplied access through edge appliances, organizations should prioritize: promptly patching internet-facing VPN, firewall, and remote-access appliances (Fortinet, Palo Alto, and Cisco products specifically, given current reporting); enforcing MFA on all remote access services; monitoring for anomalous authentication events originating from unfamiliar infrastructure; and maintaining offline, regularly tested backups to blunt the impact of the group’s double-extortion model. Because the group’s negotiation tooling is designed to escalate pressure quickly and push toward large payments, incident response teams engaging with a Global Group intrusion should involve experienced ransomware negotiators early rather than responding directly to automated chat prompts.

Sources

// Related Intelligence
Group Profile

Majinahanashi: New Japanese-Themed Ransomware Group Hits 18 Victims Since July

Group Profile

Panzer: New RaaS Operation Rapidly Expands Global Victim List

Group Profile

Titan Ransomware: A New RaaS Group Behind a Nine-Victim, Single-Day Strike on Italian Firms