Fake Globe Ransomware
Aliases: Globe Imposter, GlobeImposter
- First seen
- 2016-09-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-19 18:44:21
- Profile updated
- 2026-07-07 13:25:07
Context
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc… The ransom is 1bitcoin.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_LOLKEK (yara-rule)
- MALPEDIA_Win_Globeimposter_Auto (yara-rule)
Related threat objects
- GlobeImposter (malware)
Reports & references
- bleepingcomputer.com — The Week In Ransomware June 8Th 2018 Crybrazil Cryptconsole And Magniber (report)
- id-ransomware.blogspot.co.il — Fake Globe Ransomware (report)
- bleepingcomputer.com — The Week In Ransomware December 30Th 2016 Infected Tvs And Open Source Ransomware Sucks (report)
- twitter.com — 812421183245287424 (report)
- decrypter.emsisoft.com — Globeimposter (report)
- twitter.com — 809795402421641216 (report)
- twitter.com — 1004661259906768896 (report)
- ransomlook.io — Globeimposter (report)
- bleepingcomputer.com — Globeimposter Ransomware Spreading Via Spam Campaigns (report)
- blog.emsisoft.com — Globeimposter Ransomware (report)
- Trend Micro — Globeimposter Ransomware (report)