Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Meta fixes a bug that lets users leak AI prompts and can generate content

Mira Murati’s Thinking Machine Lab is worth $12 billion in seed round

Ultra-Volume Measurement DDOS Attack has reached record 7.3 TBPS and targets major global sectors

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » The newly launched global group Raas will expand operations with AI-driven negotiation tools
Identity

The newly launched global group Raas will expand operations with AI-driven negotiation tools

userBy userJuly 15, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Cybersecurity researchers have shed light on a new ransomware (RAAS) operation, called a global group that targets a wide range of sectors in Australia, Brazil, Europe and the United States since its emergence in early June 2025.

Global Group has been promoted at the RAMP4U forum by a threat actor known as “$$$,” said Arda Büyükkaya, researcher at EclecticiQ. “The same actor controls BlackRock Raas and controls the previously managed Mamona Ransomware Operations.”

Global Group is believed to be a BlackRock rebrand after the latter data leak site was tainted by the Dragon Force ransomware cartel in March. It is worth mentioning that BlackRock itself is a brand of another RAAS scheme known as El Dorado.

The financially motivated group has been found to be leaning heavily towards the first access broker (IAB) to deploy ransomware by weaponizing access to vulnerable edge appliances from Cisco, Fortinet, and Palo Alto Networks. It also uses brute force utilities for Microsoft Outlook and the RDWeb portal.

Cybersecurity

$$$ gained Remote Desktop Protocol (RDP) or Web Shell access to corporate networks such as corporate networks associated with law firms as a way to deploy post-exposed tools, implement lateral movements, deploy siphon data, and deploy ransomware.

Outsourcing the intrusion stage to other threat actors provides pre-competitive entry points to the enterprise network, allowing them to spend more effort on payload delivery, fear and negotiation, rather than network penetration.

The RAAS platform comes with a negotiation portal and affiliate panel. The latter allows cybercriminals to manage their victims, build ransomware payloads for VMware ESXI, NAS, BSD, and Windows, and monitor operations. To seduce more affiliates, threat actors promise an 85% revenue sharing model.

“The Global Group’s ransom negotiation panel features an automated system with an AI-driven chatbot,” the Dutch security company said. “This will allow non-affiliates who speak English to engage victims more effectively.”

As of July 14, 2025, the RAAS Group claimed 17 casualties in Australia, Brazil, Europe and the United States, spanning healthcare, oil and gas equipment manufacturing, industrial machinery and precision engineering, auto repair, accident recovery services, and large-scale business process outscoring (BPO).

The link to BlackRock and Mamona is attributed to the similarity of the source code with Mamona using the same Russian VPS provider Ipserver. Specifically, Global Group is said to be an evolution of Mamona, with the ability to enable ransomware installation across domains. Furthermore, malware is written in GO, like BlackRock.

“Creating a global group with BlackRock administrators is a deliberate strategy to modernize the business, expand revenue streams and stay competitive in the ransomware market,” said Büyükkaya. “This new brand integrates AI-powered negotiations, mobile-friendly panels and customizable payload builders, making it appealing to a wider affiliate marketing.”

This disclosure comes when the Qilin ransomware group appeared in June 2025 as the most active RAAS operation, accounting for 81 casualties. Other major players include Akira (34), Play (30), Safepi (27), and Dragon Force (25).

“SafePay saw the sharpest decline at 62.5%, suggesting a major drawback,” said Cyfirma, a cybersecurity company. “The Dragon Force appeared quickly, and attacks increased by 212.5%.”

Overall, the total number of ransomware victims fell 15%, down from 545 in May to 463 in June 2025. February is the top of this year’s list with 956 casualties.

Cybersecurity

“Despite the decline in numbers, geopolitical tensions and high-profile cyberattacks could underline increased instability and increase the risk of cyber threats,” the NCC Group said later last month.

Data collected by Optiv’s Global Threat Intelligence Center (GTIC) shows that 314 ransomware victims were listed on 74 unique data leak sites in the first quarter of 2025, representing a 213% increase in the number of victims. A total of 56 variants were observed in the first quarter of 2024.

“Ransomware operators have continued to use proven methods to gain early access to victims, including social engineering/phishing, exploitation of software vulnerabilities, compromise on unexposed, secure software, supply chain attacks, and leveraging the early access broker (IAB) community.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleRwazi raises a $12 million Series A to help businesses with consumer insights and intelligence
Next Article Ultra-Volume Measurement DDOS Attack has reached record 7.3 TBPS and targets major global sectors
user
  • Website

Related Posts

Ultra-Volume Measurement DDOS Attack has reached record 7.3 TBPS and targets major global sectors

July 15, 2025

State-backed HagyBeacon malware uses AWS Lambda to steal data from SE Asian government

July 15, 2025

How to protect invisible identity access

July 15, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Meta fixes a bug that lets users leak AI prompts and can generate content

Mira Murati’s Thinking Machine Lab is worth $12 billion in seed round

Ultra-Volume Measurement DDOS Attack has reached record 7.3 TBPS and targets major global sectors

The newly launched global group Raas will expand operations with AI-driven negotiation tools

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

The Future of Process Automation is Here: Meet TwinH

Robots Play Football in Beijing: A Glimpse into China’s Ambitious AI Future

TwinH: A New Frontier in the Pursuit of Immortality?

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.