Globe ransomware group
Globe is one of the extortion operations we watch continuously. This page covers what is known about the group and the current state of its leak site.
Who they are
Globe is a ransomware family that first appeared in August 2016, notable for its highly customizable codebase that allows operators to configure ransom note text, encryption algorithms, and file extensions. Globe uses symmetric encryption (RC4 or AES) to lock files and typically appends custom extensions such as .GLOBE, .PURPLE, .HNY, or others set by the attacker. The malware is distributed through malicious spam emails with infected attachments, compromised websites, and exploit kits. Globe’s flexibility made it attractive to low-skilled actors, resulting in many different variants in the wild. The family has primarily targeted small to medium-sized businesses and individual users across multiple regions, with no clear geographic focus.
Current status
Globe's leak site is not answering. Sites go dark for infrastructure trouble, a deliberate quiet period, or a takedown, and a good number return weeks later under the same name, so the entry stays on the list either way.
Which organisations this group has named, and when, is part of the SINON platform rather than this page. Create an account to search it, or to be told automatically if a name you care about turns up.
Sectors targeted
This group does not state an industry on its site, so we have nothing reliable to report. Most crews are opportunistic rather than sector-specific in any case — they hit what they can reach.
Watching for your name
If Globe posts your company, a supplier or a subsidiary, you want to hear it from us rather than from a journalist. SINON checks these sites continuously and alerts on the names you give it.
Start monitoring