Overview
Global Group is a ransomware-as-a-service operation that surfaced in mid-2025 and has drawn renewed attention in 2026 for a feature set unusual even by the standards of an increasingly commoditized RaaS market: an AI-driven negotiation chatbot built into the affiliate panel, and a mobile-friendly control interface that lets affiliates manage active extortions from a phone. Researchers at EclecticIQ, who have tracked the brand’s infrastructure since launch, assess with medium confidence that Global Group represents a rebrand of the Black Lock RaaS operation, pointing to shared hosting on Russian VPS provider IpServer as supporting technical evidence.
A separately branded dedicated leak site calling itself Global Secret Group (GSG) has drawn additional coverage in recent weeks, claiming an eyebrow-raising total of more than 202,000 victims. Researchers tracking the site describe that figure as unverified and likely inflated — leak sites frequently pad victim counts to project scale — but note that confirmed, independently corroborated postings continue to accumulate on both properties, with victims identified in the United States, Europe, Canada, India, the United Arab Emirates, Cyprus, and Argentina. Because naming conventions in this segment are fluid and operators frequently rebrand or spin up parallel leak sites to diffuse takedown risk, defenders should treat “Global Group” and “Global Secret Group” as closely related — and possibly identical — infrastructure rather than fully separate threats.
AI-Powered Negotiation
The operation’s most distinctive claim is an automated negotiation system built into its victim-facing chat portal. According to reporting from EclecticIQ and multiple trade outlets that reviewed the panel, the AI component is designed primarily to assist affiliates who do not speak English fluently, generating negotiation responses and applying psychological pressure tactics during ransom discussions. The stated goal is to keep negotiations moving toward the seven-figure demands the group reportedly favors for larger targets, without requiring an affiliate to personally handle real-time back-and-forth with a victim’s incident response team or negotiator.
This is a meaningful operational shift. Ransom negotiation has traditionally been a labor-intensive, skill-dependent part of running an affiliate operation — a poorly handled negotiation can collapse a payment a well-run one would have closed. Automating even part of that process lowers the skill bar for affiliates and could let less experienced operators extract higher payments than they otherwise would, a trend worth watching across the RaaS market more broadly.
Mobile Affiliate Panel and Revenue Split
Global Group’s affiliate portal is reportedly mobile-compatible, letting operators monitor infections, generate builds, and manage negotiations from a phone rather than requiring a dedicated workstation. Combined with cross-platform locker builds, this lowers the operational overhead of running an affiliate campaign considerably.
The group advertises an affiliate revenue split of 80–85%, with operators retaining the remainder — at or above the high end of the industry-standard range, and reported as an explicit pitch to rebuild trust and expand the affiliate roster following the group’s earlier rebrand. Aggressive splits like this are a recurring recruitment tactic among newer or rebranded RaaS brands trying to pull affiliates from more established operations.
Initial Access and Targeting
Public reporting describes Global Group affiliates relying heavily on initial access brokers (IABs) to obtain footholds, with particular emphasis on exposed and vulnerable edge appliances from Fortinet, Palo Alto Networks, and Cisco. This mirrors the broader 2026 trend across the ransomware ecosystem, where perimeter VPN and firewall appliances remain among the most commonly exploited entry points because they are internet-facing, frequently unpatched, and provide direct network access once compromised.
Victims identified on the group’s leak sites span a broad range of sectors — healthcare, financial services, manufacturing, real estate, professional services, construction, retail, transportation, and technology — consistent with an opportunistic, IAB-fed targeting model rather than a sector-specific campaign. Confirmed postings include healthcare providers in the United States and Australia and an automotive services firm in the United Kingdom, among others tracked by open-source monitoring services.
Assessment
Global Group’s combination of a rebrand pedigree, an aggressive affiliate split, and genuinely novel tooling — the AI negotiation assistant in particular — positions it as one of the more operationally interesting RaaS entrants of 2026, even if its self-reported victim totals should be treated with skepticism. The EclecticIQ assessment linking the group to Black Lock is notable because rebrands of previously disrupted or fading operations often inherit an experienced affiliate base and existing tooling, letting the new brand scale faster than a genuinely new entrant could.
The unverified 202,000-victim claim attached to the Global Secret Group leak site is almost certainly not a literal count of successful ransomware intrusions; leak-site victim counters are marketing artifacts as much as they are threat intelligence, and researchers have flagged the figure explicitly as unconfirmed. Analysts should continue to rely on independently corroborated postings — cross-referenced against trackers like ransomware.live and RansomLook — rather than the group’s own claimed statistics when assessing scale.
Defensive Priorities
Given the group’s reported reliance on IAB-supplied access through edge appliances, organizations should prioritize: promptly patching internet-facing VPN, firewall, and remote-access appliances (Fortinet, Palo Alto, and Cisco products specifically, given current reporting); enforcing MFA on all remote access services; monitoring for anomalous authentication events originating from unfamiliar infrastructure; and maintaining offline, regularly tested backups to blunt the impact of the group’s double-extortion model. Because the group’s negotiation tooling is designed to escalate pressure quickly and push toward large payments, incident response teams engaging with a Global Group intrusion should involve experienced ransomware negotiators early rather than responding directly to automated chat prompts.
Sources
- EclecticIQ — GLOBAL GROUP: Emerging Ransomware-as-a-Service, supporting AI driven negotiation and mobile control panel for their affiliates
- Cyber Security News — GLOBAL GROUP RaaS Operators Enable AI-powered Negotiation Functionality
- CyberInsider — New Ransomware Operation ‘Global Group’ Launches with AI Negotiators
- SOCRadar — Global Secret Group Ransomware Group Profile
- GalaxyWarden — Global Secret Group Ransomware Breach Tracker