Ransomware Group Uses AI Chatbot to Intensify Pressure on Victims
A threat actor claiming to have launched a new ransomware-as-a-service (RaaS) venture is leveraging AI chatbots in its negotiation panel to automate communication and apply psychological pressure on victims.
In June 2025, a ransomware actor known by the alias $$$ publicly introduced a new RaaS brand, GLOBAL GROUP, on the Russian Anonymous Market Place (RAMP or Ramp4u) cybercrime forum.
Researchers at Picus Security promptly conducted a forensic investigation across malware samples, infrastructure configuration, and control logic, which included analyzing leaked API metadata, reverse-engineered binary code, and threat actor behavior.
They concluded that GLOBAL GROUP had very few new features but instead included capabilities found in the Mamona RIP and Black Lock ransomware families.
To read the complete article, see this link.