New .DOC GlobeImposter Ransomware Variant Malspam Campaign Underway

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
A new malspam campaign is underway that is distributing a GlobeImposter variant that appends the ..doc extension to encrypted files. This malspam is pretending to photos being sent to the recipient and will have a subject line that starts in a similar way to "Emailing: IMG_20171221_".

malspam.jpg

GlobeImposter MalSpam
These malspam emails contain7zip (.7z) archive attachments that are named after a camera photo's filename such as IMG_[date]_[number]. These 7z files contain a obfuscated .js file that when double-clicked on will cause the GlobeImposter ransomware to be downloaded from a remote site and executed.

Unfortunately, at this time there is no way to decrypt GlobeImposter files for free. For support or help with this ransomware infection, you can ask in our dedicated GlobeImposter Ransomware Support topic.
 

Prorootect

Level 69
Verified
Nov 5, 2011
5,855
This is ancient story ( from April-July 2017): GlobeImposter Ransomware Support (.Crypt & .PSCrypt ext - !back_files!.html ) - Ransomware Help & Tech Support
This ancient (so not new) story on Bleepingcomputer.com article are with recent date... so "News articleware imposter" - by omission?.. on Bleepingcomputer.com...

For decryption, look eg. Malwarebytes blog read: Ransom.GlobeImposter: Ransom.GlobeImposter - Malwarebytes Labs
"GlobeImposter, also known as Fake Globe, mimics the Globe ransomware variant. It is distributed through a malicious spam campaign, recognizable only with their lack of message content and an attached ZIP file. This type of spam is called a “blank slate.” GlobeImposter is also distributed via exploits and malicious advertising, fake updates, and repacked infected installers."

"Remediation

Malwarebytes users are already protected against the GlobeImposter ransomware."

EDIT:
On MT we have some ancient topics about this GlobeImposter ransomware.
- or maybe exist a few diverse distributions of GlobeImposter ransomware?
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top