Researchers have warned of a ransomware threat that targets VPN credentials and edge devices.

Cybersecurity firm EclectiqIQ published a report this week on Global Group, a Ransomware-as-a-Service (RaaS) operator that is a potential rebrand of the notorious BlackLock ransomware group.

Like BlackLock, the Global malware acquires network access from Initial Access Brokers to enterprise VPN appliances such as those from Fortinet, Palo Alto, and Cisco.

Once inside a network, it encrypts systems across Windows, Linux, and VMware servers, and often steals sensitive data for double extortion.

ElectiqIQ’s researchers report a caveat that the new Global strain is an AI chatbot panel designed for ransom negotiation with victims.

Possibly Russia-affiliated, the Group is targeting businesses in the US, UK, Australia, and Brazil, though none of those attacks have been linked by EclecticIQ to any specific vendor’s appliance.

Since the RaaS was released in late June, 17 victims have been targeted, primarily in healthcare and manufacturing services. These companies have been listed on a Dedicated Leak Site (DLS) hosted by Global on the Tor network.

VPN cybersecurity threats and solutions

Broadcom has responded to the report by noting that standard settings in its VMware Carbon Black security solution are capable of blocking the Global ransomware payload before it executes.

It also points to standard defenses at the network and cloud levels in its Symantec cloud offering that can detect and block the group’s brute-force attempts.

Network managers with custom settings are recommended to block Known malware, Suspect threats, and potentially unwanted programs (PUPs).

Fortinet, Palo Alto, and Cisco have reacted to similar ransomware threats outside of BlackLock/Global, with Fortinet for example issuing patches for bypass vulnerabilities in FortiOS and FortiProxy this year.

While Global Group is a relatively new ransomware player, its past life as BlackLock can indicate what kind of threat is posed by the new Global strain. Created in March 2024 under its original name of El Dorado, BlackLock became one of the world’s top ransomware groups by Q4 of last year, seeing a 1,425% increase in activity from Q3.

The new Global threat comes after a recent ransomware attack on Ingram Micro, in which attackers breached Ingram’s systems through its GlobalProtect VPN platform.