globe

First seen
2016-08-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:57:41

Targeted industries: professional-services retail-and-hospitality healthcare-and-pharmaceutical manufacturing technology-and-telecommunications media-and-entertainment

Context

Globe is a ransomware family that first appeared in August 2016, notable for its highly customizable codebase that allows operators to configure ransom note text, encryption algorithms, and file extensions. Globe uses symmetric encryption (RC4 or AES) to lock files and typically appends custom extensions such as .GLOBE, .PURPLE, .HNY, or others set by the attacker. The malware is distributed through malicious spam emails with infected attachments, compromised websites, and exploit kits. Globe’s flexibility made it attractive to low-skilled actors, resulting in many different variants in the wild. The family has primarily targeted small to medium-sized businesses and individual users across multiple regions, with no clear geographic focus.

Reports & references

  • ransomlook.io — Globe (report)
  • bleepingcomputer.com — Globe Ransomware Gives You The Opportunity To Customize Your Encryption (report)
  • pcrisk.com — 10512 Globe Ransomware (report)
  • Trend Micro — Ransomware Globe (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Globe Ransom (report)

External references