Global Group Abuses Legitimate WinMerge Tool to Deploy Ransomware via Phishing
The Global Group threat actors are exploiting trusted, legitimate software (WinMerge) as a living-off-the-land technique to bypass security controls and deploy ransomware, initiated through payment-themed phishing emails carrying malicious ISO files. This attack chain is particularly dangerous because security tools may whitelist WinMerge, allowing the encryptor to execute without triggering alerts. The use of ISO files is a deliberate evasion tactic to bypass email attachment scanning and mark-of-the-web (MotW) protections. Targeting large enterprises amplifies the potential for massive extortion payouts, making employee phishing awareness and endpoint configuration controls critical defensive layers.
Tactical Insight
Immediate actions
- Block or quarantine ISO, IMG, and other disk image file types at the email gateway to prevent malicious container files from reaching end users.
- Apply application allowlisting policies to restrict unauthorized or unexpected use of legitimate tools like WinMerge in enterprise environments.
- Deploy or update anti-phishing filters to flag payment-themed lures and suspicious email patterns consistent with this campaign.
Long-term improvements
- Enforce Group Policy or endpoint management settings to disable automatic mounting of ISO/virtual disk files on Windows endpoints.
- Conduct regular, role-targeted phishing simulation training focused on financial and payment-themed lures for employees in finance and procurement roles.
- Implement strict software inventory and control policies so that unapproved third-party utilities cannot be silently leveraged by malicious payloads.
Detection measures
- Monitor endpoint telemetry for unusual parent-child process relationships involving known legitimate tools (e.g., WinMerge spawning unexpected child processes).
- Enable and tune SIEM alerting for ransomware behavioral indicators such as rapid file encryption, shadow copy deletion, and unusual volume activity.
- Establish network-level monitoring to detect lateral movement and command-and-control beaconing patterns associated with ransomware pre-deployment stages.