Weaponized Windows shortcuts reportedly deliver Global Group ransomware

THE BRIEF
CSO Online reports that Forcepoint X-Labs researchers identified a large Phorpiex botnet-aided phishing campaign that uses weaponized Windows shortcut files to deliver Global Group ransomware across systems. The activity was observed in late 2024, and the report says it continued into 2026. The campaign reportedly used the subject line “Your Document” with a malicious LNK attachment, relying on recipients to open it. Forcepoint described a sequence combining social engineering, stealthy execution, and living-off-the-land techniques. The shortcut silently retrieved and launched a second-stage payload, according to the researchers. Unlike operations that depend on external command-and-control infrastructure, the reported Global Group payload executed locally after delivery, which researchers said can complicate detection and response for network-centric security controls. The report does not establish the campaign’s full scope or outcomes. The findings highlight the need to examine shortcut attachments and endpoint behavior, rather than relying only on network indicators, when assessing similar emails.
WHY IT MATTERS
The reported campaign combines a familiar phishing lure with a file type that can trigger execution when opened and techniques designed to reduce obvious network signals. Forcepoint’s observation that the payload executes locally suggests that controls focused primarily on external command-and-control traffic may not provide enough visibility. Organizations may therefore need to review how email security, endpoint monitoring, and incident response address LNK attachments, living-off-the-land activity, and second-stage payload execution. The report describes an ongoing campaign, but does not establish its full reach or impact.
WHO SHOULD CARE
Security operations, endpoint security, email security, and incident response teams should review protections for malicious LNK attachments and local payload execution. Security leaders should also assess whether network-centric monitoring is sufficient for this scenario.
WHAT TO DO NOW
- Review email controls for Windows shortcut files, especially attachments using document-themed subjects such as “Your Document.”
- Confirm endpoint monitoring can detect shortcut files that retrieve or launch second-stage payloads.
- Look for living-off-the-land execution patterns on endpoints associated with suspicious email activity.
- Test incident-response procedures for ransomware delivered through local execution rather than obvious external command-and-control traffic.