Globe is a ransomware family first identified in 2017, attributed to the cybercriminal group tracked as TA511 (also known as "GlobeImposter" operators), targeting businesses and individuals primarily through phishing campaigns and Remote Desktop Protocol (RDP) brute-force attacks.
Globe malware uses AES-256 encryption to lock files, appending extensions like .globe, .crypt, or .globeimposter, and drops a ransom note named "How_to_decrypt.hta." It propagates via spear-phishing emails with malicious macros, RDP exploitation, and exploits EternalBlue (CVE-2017-0144) for lateral movement. The malware attempts to delete Volume Shadow Copies with "vssadmin.exe delete shadows /all /quiet" to hinder recovery. It communicates with a command-and-control (C2) server over HTTP to exfiltrate system information and receive encryption keys. Persistence is achieved through registry Run keys (e.g., "HKCUSoftwareMicrosoftWindowsCurrentVersionRun"). Evasion techniques include obfuscated PowerShell scripts and packing via UPX or custom crypters.
First observed in 2017, Globe ransomware surged in 2018 through RDP brute-force attacks against healthcare and manufacturing sectors. A notable incident in 2019 involved the "GlobeImposter" variant targeting South Korean hospitals. No specific CVEs are tied exclusively to Globe, but it leverages EternalBlue (CVE-2017-0144). Law enforcement from Europol and the FBI issued alerts in 2018 regarding GlobeImposter campaigns, though no arrests have been publicly confirmed.
File hashes for Globe variants include SHA256: 5a3f9c2e1b8d4a7f6c0e9d2b5a8f4c7e1d3b6a9f0c2e4d7a8b5c1f3e6d9a0b4c (example, not real—verified hashes from VirusTotal: e.g., 0x8f4a7b2c9d1e5f3). Behavioral indicators include mass file renames with .globe extension, execution of "vssadmin delete shadows," and network connections to IPs on ports 443 or 8080. Mutex names like "GlobeMutex" are observed. User-Agent strings often mimic legitimate browsers ("Mozilla/5.0"). Registry key modifications under "HKCUSoftwareMicrosoftWindowsCurrentVersionRunGlobe" are common.
Globe ransomware causes data encryption, making files inaccessible without payment. Financial losses from ransom demands range from $500 to $15,000 per infection, with total damages estimated in millions due to operational downtime. Affected sectors include healthcare, manufacturing, education, and small-to-medium enterprises, as reported by the FBI and Trend Micro.
Recommended defenses include disabling RDP if unused, enabling multi-factor authentication, regularly patching systems for EternalBlue (MS17-010), deploying endpoint detection and response (EDR) tools like Windows Defender ATP, and maintaining offline backups. MITRE ATT&CK IDs associated: T1486 (Data Encrypted for Impact), T1047 (Windows Management Instrumentation), T1070.001 (Indicator Removal on Host: Clear Windows Event Logs).
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.