[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVaMBJQBMIXTK_WxvhGsJ2SgXCVQc1vQf9EOonZ8VHF4":3},{"article":4,"iocs":40},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":23,"category":24,"article_tags":27},"3fb38a49-67e4-4fba-b84d-e8cdefd91678","Global Group Ransomware Abuses WinMerge to Deploy Encryptor","global-group-ransomware-abuses-winmerge-to-deploy-encryptor-c396c8","Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.","Researchers at Cofense have uncovered a new tactic employed by the threat group Global Group. They are leveraging payment-themed phishing emails containing malicious ISO files that, when opened, utilize the legitimate WinMerge software to deploy their ransomware encryptor. This method targets large enterprises, aiming to extort them through ransomware attacks.","Global Group ransomware uses WinMerge to deploy encryptor via payment-themed phishing.",null,"https:\u002F\u002Fhackread.com\u002Fglobal-group-ransomware-winmerge-deploy-encryptor\u002F","2026-09-30T15:44:45+00:00","2026-09-30T16:00:11.736028+00:00",8,[17,20],{"name":18,"type":19},"Global Group","threat_actor",{"name":21,"type":22},"WinMerge","product","7d8b5ab8-ea0b-4ced-ae97-ec251b86993a",{"id":23,"icon":11,"name":25,"slug":26},"Ransomware","ransomware",[28,30,35],{"category":29},{"id":23,"icon":11,"name":25,"slug":26},{"category":31},{"id":32,"icon":11,"name":33,"slug":34},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":36},{"id":37,"icon":11,"name":38,"slug":39},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[41],{"type":34,"value":42,"context":43},"Global Group ransomware","Ransomware deployed by the threat actor"]