Fake Globe Ransomware

Aliases: Globe Imposter, GlobeImposter

First seen
2016-09-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-19 18:44:21
Profile updated
2026-07-07 13:25:07

Context

It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc… The ransom is 1bitcoin.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_LOLKEK (yara-rule)
  • MALPEDIA_Win_Globeimposter_Auto (yara-rule)

Related threat objects

Reports & references

  • bleepingcomputer.com — The Week In Ransomware June 8Th 2018 Crybrazil Cryptconsole And Magniber (report)
  • id-ransomware.blogspot.co.il — Fake Globe Ransomware (report)
  • bleepingcomputer.com — The Week In Ransomware December 30Th 2016 Infected Tvs And Open Source Ransomware Sucks (report)
  • twitter.com — 812421183245287424 (report)
  • decrypter.emsisoft.com — Globeimposter (report)
  • twitter.com — 809795402421641216 (report)
  • twitter.com — 1004661259906768896 (report)
  • ransomlook.io — Globeimposter (report)
  • bleepingcomputer.com — Globeimposter Ransomware Spreading Via Spam Campaigns (report)
  • blog.emsisoft.com — Globeimposter Ransomware (report)
  • Trend Micro — Globeimposter Ransomware (report)

External references