Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 17:25:47 UTC Home > List all groups > List all tools > List all groups using tool GlobeImposter Tool: GlobeImposter Names GlobeImposter Fake Globe Category Malware Type Ransomware Description (Malwarebytes) Ransom.GlobeImposter is a ransomware application that will encrypt files on a victim machine and demand payment to retrieve the information. Ransom.GlobeImposter is also known as Fake Globe due to how the software mimics the Globe ransomware family. Ransom.GlobeImposter may be distributed through a malicious spam campaign, recognizable only with their lack of message content and an attached ZIP file. This type of spam is called a “blank slate.” Ransom.GlobeImposter is also distributed via exploits and malicious advertising, fake updates, and repacked infected installers. Information Malpedia AlienVault OTX Playbook Last change to this tool card: 25 April 2023 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6b34667c-43b9-4922-b9ee-465414f601a5 Page 1 of 2 Download this tool card in JSON format All groups using tool GlobeImposter Changed Name Country Observed APT groups   TA505, Graceful Spider, Gold Evergreen 2006-Nov 2022 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6b34667c-43b9-4922-b9ee-465414f601a5 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6b34667c-43b9-4922-b9ee-465414f601a5 Page 2 of 2