Globeimposter
Description
GlobeImposter is a ransomware family that first appeared in mid-2017, designed to mimic the appearance and naming conventions of the earlier Globe ransomware but built on entirely different code. It uses strong encryption algorithms, typically AES combined with RSA, and appends a variety of file extensions to encrypted data—such as .crypt, .doc, .png, .jpg, .spreadsheet, and many more—depending on the campaign. GlobeImposter is primarily distributed via malicious spam campaigns with infected attachments, compromised RDP services, and exploit kits. It drops a ransom note (often named how_to_back_files.html or similar) instructing victims to contact the attackers via email. Over the years, GlobeImposter has spawned hundreds of variants, making it one of the more persistent commodity ransomware threats targeting small businesses and individuals globally.
External Analysis |
https://www.bleepingcomputer.com/news/security/globeimposter-ransomware-spreading-via-spam-campaigns/ |
https://blog.emsisoft.com/en/23639/globeimposter-ransomware/ |
https://www.trendmicro.com/en_us/research/17/g/globeimposter-ransomware.html |