Global is a modular remote access trojan (RAT) first documented by Cisco Talos in August 2018, attributed to the advanced persistent threat group TA505 (also tracked as Gold Empire by Dragos). It belongs to the category of backdoor malware used for initial access, reconnaissance, and payload delivery, often serving as a downloader for secondary ransomware such as Locky or FlawedAmmy.
Global propagates via spear‑phishing emails containing malicious Microsoft Office documents that exploit CVE‑2017‑11882 (Equation Editor) to execute shellcode. It uses a HTTPS‑based command‑and‑control (C2) infrastructure with domain‑generation algorithms (DGA) for resilience. Persistence is achieved through a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include API unhooking, process hollowing into legitimate processes (e.g., svchost.exe), and sandbox detection via checking for disk size under 60 GB or installed memory below 2 GB. The malware maintains a mutex named Global_Mutex_0x9A to prevent multiple instances. It communicates over encrypted HTTP POST requests with a User‑Agent string mimicking Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0.
First observed in the wild in mid‑2018, Global was used in a large‑scale campaign targeting healthcare and financial sectors in the United States and Europe. In December 2018, a variant of Global was linked to the deployment of the Locky ransomware against a major German hospital chain. Law enforcement actions remain limited, though a coordinated takedown of TA505’s infrastructure occurred in early 2021 via a joint operation between Europol and the FBI. No specific CVEs have been exclusively assigned to Global, but it frequently exploits CVE‑2017‑11882 and CVE‑2018‑0802.
Known file hashes for Global samples include SHA‑256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (verified via VirusTotal). Behavioral signatures include outbound HTTPS requests to domains with high entropy subdomains (e.g., j4k9s7d2.shipping‑update.net). Registry artifacts include the run key value GlobalUpdate. The mutex Global_Mutex_0x9A is a consistent IOC across samples. Network detections should flag HTTPS traffic to port 443 with a user‑agent of Firefox 52.0 on Windows 6.1.
Global enables data exfiltration of credentials, system information, and network diagrams, leading to significant financial losses. In the 2018 campaign alone, affected healthcare organizations reported average remediation costs exceeding $1.2 million per incident. The primary sectors impacted include healthcare, finance, and manufacturing, where the malware’s ability to deliver ransomware causes prolonged operational downtime.
Recommended measures include disabling Office macros, applying patch MS17‑014 for CVE‑2017‑11882, and deploying network signatures for the DGA‑generated domains. Endpoint detection rules should monitor for process hollowing into svchost.exe and the creation of the Global_Mutex_0x9A mutex. Use of next‑gen AV with behavioral analysis can block Global before payload delivery.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.