Ransomware family
GlobeImposter Ransomware Decryption & Data Recovery
- Active
- High
- Some versions decryptable
GlobeImposter has been active since 2017 and is highly prevalent in China through its Chinese-zodiac variants (such as .Dragon4444) and Olympian-gods variants (such as .Ares666). It spreads by brute-forcing RDP/SMB and moving laterally, and caused widespread hospital infections in China in 2018. Mainstream variants have no decryptor.
- First seen
- 2017-05
- File extensions
- .Dragon4444 .Snake4444 .Rat4444
- Ransom notes
- how_to_back_files.html
- Affected platforms
- Windows / Databases
Family profile
- File extensions
- .Dragon4444
- .Snake4444
- .Rat4444
- .Ox4444
- .Tiger4444
- .Ares666
- .Zeus666
- .Apollon666
- .Aphrodite666
- .C4H
- .crypt
- .kat6.l6st6r
- Ransom notes
- how_to_back_files.html
- HOW TO BACK YOUR FILES.txt
- RECOVERY-FILES.html
- Contact patterns
- Disposable mailboxes in the note (free encrypted-mail domains, primary and backup)
- Link to a Tor negotiation page in some variants
- Aliases / versions
- GlobeImposter 2.0、GlobeImposter 3.0、十二生肖系列(4444 家族)、十二主神系列(666 家族)、C4H 变种
- First seen
- 2017-05
- Status
- Active
- Threat level
- High
- Affected platforms
- Windows
- Databases
- Tags
- Prevalent in China
- RDP brute force
- Targets databases
- Legacy family
- Active
Emsisoft published a GlobeImposter decryptor, but its scope is very narrow:
- It applies only to early variants that use the .crypt extension and leave the base filename unchanged.
- It requires a pair consisting of an encrypted file and its unencrypted original to recover the key.
- The tool dates from December 2016, and Emsisoft states that such tools may not support variants released after they were built.
It does not apply to the GlobeImposter 2.0/3.0 builds, the Chinese-zodiac (4444) series or the Olympian-gods (666) series that are prevalent in China. Those variants protect keys with RSA-2048, and Chinese vendor analyses agree there is no decryption tool. When you see .Dragon4444, .Ares666 or .C4H, move straight to backup restoration and database repair assessment rather than spending time on decryptors.
Latest activity
360's August 2026 China report ranks Weaxor (65.74%), BrzCrypt and LockBit top; GlobeImposter is absent from the chart. Do not assume GlobeImposter on RDP cases - confirm the family from the extension and note.
SourcesChinese IR write-up: an exposed server was encrypted by GlobeImposter 3.0 (zodiac), from a sample implanted ~2019 and dormant six years on a host hit once before. Cleaning alone is not enough - rebuild and trace entry.
Sources
Overview
GlobeImposter first appeared in May 2017, named for the way early builds imitated the ransom notes of the Globe family. It iterated into two main generations, 2.0 and 3.0, and became known for themed variant groups: the Chinese-zodiac series (the 4444 family) combines a zodiac animal with 4444 — .Dragon4444, .Snake4444, .Rat4444 — deliberately exploiting the cultural aversion to the number four; and the Olympian-gods series (the 666 family) uses Greek deity names with 666 — .Ares666, .Zeus666, .Apollon666 — which Sangfor and other vendors covered in dedicated advisories on campaigns against large hospitals.
A defining incident: in February 2018 GlobeImposter 2.0 broke out across multiple large Chinese hospitals, encrypting core HIS, LIS and PACS systems and forcing some onto manual processes. It became a turning point for healthcare cybersecurity investment in China. The family kept producing variants, with suffixes such as .C4H appearing in 2019, and remains active today. Victims are mostly business servers in healthcare, education, manufacturing and regional public-sector bodies, sharing a flat internal network, exposed or weakly protected RDP, and backups on the same machine as production.
How to identify it
Extensions follow clear themed-group patterns: the zodiac series .Dragon4444, .Snake4444, .Rat4444, .Ox4444, .Tiger4444; the Olympian-gods series .Ares666, .Zeus666, .Apollon666, .Aphrodite666, .Hades666; and other variants .C4H, .crypt, .danger, .loches, .777. An "English word plus 4444" or "Greek deity plus 666" combination is effectively a GlobeImposter identification. A further suffix, .kat6.l6st6r (notes "HOW TO BACK YOUR FILES.exe" and ids.txt, contact addresses such as KAT6.L6ST6R@AOL.COM), is attributed to this family by Chinese vendors; we have not seen independent confirmation from international vendors.
Ransom notes: the classic is how_to_back_files.html, dropped into every encrypted directory and rendered as a ransom page in a browser; some variants use names such as HOW TO BACK YOUR FILES.txt. Notes typically give a primary and backup anonymous mailbox and ask for a machine ID.
Intrusion artefacts: clustered RDP logon failures (4625) followed by a success (4624); multiple internal servers encrypted in a similar window with shared-credential relationships, indicating lateral movement rather than worm propagation; traces of credential-dumping and network-scanning tools; other families such as MedusaLocker present on the same host in some cases; and database and backup services terminated with shadow copies deleted.
Infection vectors
The typical GlobeImposter chain is brute-forced RDP/SMB, lateral movement, then hands-on deployment: scan the internet for servers with port 3389 open and brute-force administrator and similar accounts; disable security software and dump local credentials; move laterally with those credentials over SMB, RDP, scheduled tasks and PsExec-class tools; take the domain controller or core servers where possible to widen the encryption scope; then terminate database, mail and backup services, delete shadow copies and encrypt.
Why healthcare and education in China are hit hardest: both run large internal networks with complex legacy estates and share several weaknesses — RDP opened on business systems for convenient remote maintenance; a single shared administrator password across medical devices and teaching terminals; no segmentation, so one compromised server reaches almost every host; and backup systems using the same credentials as production. GlobeImposter's lateral capability maps directly onto these gaps. Other entry points include phishing and exposed web application vulnerabilities.
Encryption behavior
GlobeImposter uses a hybrid scheme: RSA-2048 protects the keys while a symmetric cipher encrypts file contents. Chinese vendor analyses consistently note that, because of RSA-2048, mainstream variants have no decryption tool; key material is per-host, so cross-host decryption is impossible.
Encryption and destructive behaviour: it terminates database (SQL Server, Oracle, MySQL), mail and backup-agent services before encrypting; encrypts local disks, mapped network drives and reachable SMB shares; deletes volume shadow copies and restore points; explicitly targets database and backup files (.mdf, .ldf, .bak, .dbf, .ibd); writes how_to_back_files.html into every encrypted directory; and in some variants skips critical system directories so the host still boots and displays the note.
On large-file handling: GlobeImposter has many variants whose implementations differ by generation, and public sources give no consistent answer, so testing is required — take .mdf, .dbf and .ibd files and imaging data, then analyse the distribution and stride of encrypted blocks before judging whether structure-level repair is viable.
Assess before you act
Recoverability assessment
Mainstream variants have no usable free decryptor. Emsisoft's GlobeImposter decryptor covers only early .crypt-extension variants and requires a matching pair of an encrypted file and its unencrypted original; it does not apply to the .Dragon4444, .Ares666 or .C4H variants prevalent in China. The realistic paths follow.
1. Backups, snapshots and shadow copies The primary path, and the most common successful one in healthcare and education cases. Because GlobeImposter relies on credentials for lateral movement, backup systems outside the same credential domain that require separate authentication often survive. Check standalone backup servers, offline tape and removable media, NAS-native snapshots, cloud object-storage version history with object lock, hypervisor snapshots, and vendor-hosted off-site DR.
2. Structure-level repair of large files (verify first) PACS image stores and HIS/LIS databases in healthcare, and academic administration and resource repositories in education, are enormous file collections. Where large files are only partially encrypted, page- or block-level damage mapping, structural repair and data extraction become possible; where encryption is full the path is closed. Sampling must precede any coverage estimate.
3. Hosts never reached laterally, plus side-channel copies Servers using standalone local accounts, non-domain devices, endpoints powered off at the time and Linux servers are usually intact and can serve as a baseline. Side-channel data is disproportionately valuable where backups are missing, such as local caches on imaging equipment, data submitted to regional platforms, and printed reports.
We do not pay ransoms, do not negotiate for clients, and never promise that every file can be decrypted or restored.
Our response plan
Hit by GlobeImposter ransomware? What to do
Step 1: Containment and evidence preservation
Because GlobeImposter moves laterally on credentials, containment means cutting credential reachability, not just pulling network cables. Immediately remove public 3389 mappings, block SMB and RDP between affected segments, reset domain administrator and all privileged account passwords (from a clean host), and disable suspicious accounts.
In large healthcare and education networks, assess in parallel which hosts have been accessed but not yet encrypted, so the incident does not continue spreading into HIS/LIS/PACS or academic systems during response.
Evidence to preserve: security log 4625/4624 records, domain controller logon and ticket request records, on-disk traces of credential-dumping and network-scanning tools, account and group changes, scheduled task and service inventories, the original how_to_back_files.html notes, encrypted samples of varying type and size, and matching unencrypted originals. Do not reinstall, do not reformat, and do not write to original disks.
Step 2: Family identification and encryption analysis
GlobeImposter's themed suffixes (zodiac plus 4444, deity plus 666) together with the how_to_back_files.html note usually make identification straightforward. What needs confirming is the generation (2.0 or 3.0) and variant, and whether another family such as MedusaLocker is present in the same incident — some cases share an initial-access channel, widening the response scope.
It is equally important to rule out the false hope that the Emsisoft decryptor applies: it covers only early .crypt variants and requires a file pair, and does nothing for the 4444/666 series.
Encryption analysis follows: sample database files, imaging files, large archives and ordinary documents to determine whether encryption is partial or full, the block stride, and where damaged structures sit. This decides whether Step 3 can offer large-file repair. Lateral scoping is completed at the same time: which hosts were encrypted, which were accessed, and which credentials the attacker holds.
Step 3: Recoverability assessment and recovery planning
After stating plainly that mainstream variants have no decryptor, bucket by business priority and path:
- Backup available: verify the recovery point and integrity of standalone backup systems, offline media, NAS snapshots, cloud version history, hypervisor snapshots and off-site DR, confirming they were not reachable with the same credentials.
- Repair required: sample HIS/LIS databases, PACS image stores, and academic and finance databases; give table- or file-level coverage estimates where encryption is partial and state the position honestly where it is full.
- Side-channel reconstruction: in healthcare, submitted data, device-local caches and printed archives; in education, filed reports and copies on staff endpoints; in companies, report exports and reconciliation data.
- Unaffected hosts: verify host by host which can serve as a baseline.
- Confirmed unrecoverable: listed explicitly.
Healthcare and education plans must also set business-continuity priorities — which systems have to come back first to sustain basic service (outpatient registration, laboratory reporting) and which can wait.
Step 4: Recovery execution
Execution happens in a clean environment where credentials have been reset and backdoors and persistence removed, working throughout on read-only images and copies.
- Backup restoration: validate backup integrity and screen for embedded payloads in isolation first, then restore in batches by business-continuity priority.
- Database repair: where encryption is confirmed partial, map page-level damage in SQL Server, repair system tables and allocation structures and extract table by table; for Oracle, combine datafile header repair with archive-log application; for MySQL, process .ibd files individually.
- Imaging and file repositories: run bulk repair feasibility processing for PACS and teaching-resource stores, delivering by department, campus or faculty.
- Delta reconstruction: replay transaction logs, archive logs and submitted data.
- Side-channel reload: import reconstructed reports and records back into the system by business period.
Each batch is validated in business terms: medical record and report counts in healthcare, enrolment and grade record counts in education, document and ledger data in companies, plus application functionality tests. The recovery environment joins production only once confirmed clean.
Step 5: Attribution, hardening and sign-off
The investigation report states: the initial entry point (which server's RDP was brute-forced), how credentials were obtained, the lateral path and the inventory of hosts reached, whether the domain controller was taken, dwell time, why backups failed, and whether data was exfiltrated.
Verifiable hardening checklist:
- Remove all public 3389 mappings and route remote access through VPN or a zero-trust gateway with enforced multi-factor authentication.
- Eliminate shared administrator passwords: medical devices, teaching terminals and servers must not share one credential set; implement tiered privileged accounts with regular rotation.
- Segment the network so business, device, office and backup networks are isolated, limiting SMB and RDP reachability.
- Rebuild the backup architecture on offline/off-site plus immutable storage, with the backup system using separate credentials and staying off the domain, and run regular real restore drills.
- Harden the domain: restrict where privileged accounts can log on, randomise local administrator passwords with a LAPS-style mechanism, and disable unnecessary administrative shares.
- Deploy EDR across servers and key endpoints with a closed alert loop on brute forcing, credential dumping and bulk file renaming.
The engagement closes with an incident report and a hardening sign-off checklist.
Risk warning
What not to do
- Do not expect Emsisoft's GlobeImposter decryptor to open .Dragon4444, .Ares666 or .C4H files. It covers only early .crypt variants and requires a file pair; it does nothing for the variants prevalent in China.
- Do not reset passwords only on the encrypted hosts. GlobeImposter moves on credentials, so domain administrator and all privileged account passwords must be reset from a clean host or the attacker can simply return.
- Do not restore host by host before the lateral scope is confirmed. Machines that were accessed but not encrypted may still carry backdoors, and re-encryption during recovery is common.
- Do not reinstall the OS or reformat affected volumes, and do not rebuild partitions to "clean up" — forensic evidence and the fragment-recovery option go with them.
- Do not delete how_to_back_files.html or encrypted samples; they are required inputs for variant identification and encryption analysis.
- Do not email the addresses in the note to pay on your own; payment guarantees no working decryptor and does not stop the attacker reusing the same entry point.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
Database Encrypted by Ransomware
When database files are encrypted, every business system that depends on them stops at once. This page explains how we triage an encrypted database, how recoverability is assessed, and when file repair, backup-plus-log restore, or rebuild is the right path.
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
Related industries
Healthcare Ransomware Response and Recovery
When a hospital is hit, registration, consultation, orders, billing, laboratory and imaging fail at the same moment and care falls back to paper. This page covers the healthcare threat picture, a recovery priority built around clinical continuity, and the handling of patient data and compliance obligations.
Education and Research Ransomware Response
Schools and research institutions run open networks with dispersed endpoints and systems built across many eras, often unattended at night and during holidays — a combination attackers exploit. This page covers the sector's threat profile, recovery priorities for academic and research data, and defences suited to campus networks.
Manufacturing Ransomware Response and Recovery
Ransomware in manufacturing hits information systems and production cadence at the same time: with ERP down there are no orders, with MES down there is no schedule, and an encrypted drawing library takes the process documentation for an entire product line with it. This page covers the asset profile, recovery priorities and targeted defences.
Similar families
- Some versions decryptable
Crysis / Dharma
Crysis (CrySiS) and its successor Dharma have been active since 2016, breaking in through brute-forced RDP and spawning many variants including .cezar, .arena, .bip, .combo and .java. Early versions have free decryptors; the .cezar family from 2017 onward does not.
- Free decryptor available
Phobos
Phobos is a RaaS family that relies mainly on brute-forced RDP and has spawned a long list of variants (.eking, .faust, .elbie, .devos and more). It has been a persistent presence in Chinese server-ransomware cases, and in July 2025 Japan's National Police Agency released a free decryptor covering part of the lineage.
- No public decryptor
BeijingCrypt
BeijingCrypt takes its name from the .beijing extension used by early builds. It is a persistently prevalent family in China, deployed by hand after brute-forcing remote desktop or database credentials, and has cycled through .beijing, .360, .520, .halo and .bixi variants. No public decryptor exists.
FAQ
GlobeImposter Frequently asked questions
Can .Dragon4444 / .Ares666 files be decrypted?
No usable free decryptor exists. These extensions belong to GlobeImposter's Chinese-zodiac (4444) and Olympian-gods (666) series respectively; both protect keys with RSA-2048, and Chinese vendor analyses agree there is no decryption method.
One common misconception is worth correcting: Emsisoft did publish a GlobeImposter decryptor, but it applies only to early variants using the .crypt extension with unchanged base filenames, and it requires a matching pair of an encrypted file and its unencrypted original. It does not apply to the 4444 or 666 series and attempting it will not succeed.
The correct approach is to invest the time in realistic paths: inventory standalone backup systems and offline media, check NAS and hypervisor snapshots, run repair feasibility tests on databases and image stores, and map hosts never reached laterally along with side-channel copies.
GlobeImposter encrypted our hospital HIS/PACS systems — can they be recovered?
Assessed by path, healthcare cases usually have more room than expected.
Backups come first. Because GlobeImposter moves on credentials, backup systems outside the same credential domain that require separate authentication often survive. Check standalone backup servers, offline tape, storage array snapshots, hypervisor snapshots and vendor-hosted off-site DR.
Large-file repair is next. HIS/LIS databases and PACS image stores are enormous, and the outlook depends on how encryption was applied — partial encryption allows page- or block-level damage mapping and data extraction, while full encryption closes the path. Coverage estimates require sampling and testing first.
Third are healthcare-specific side channels: local caches on imaging equipment and workstation copies, data submitted to regional platforms and insurance systems, printed and archived reports and records, and data retained by laboratory instruments themselves. Where backups are missing these are disproportionately valuable.
Business continuity runs alongside: restore outpatient registration, billing and laboratory report release first, then work through the rest in batches.
Why were dozens of internal servers encrypted almost simultaneously?
Because GlobeImposter is a hands-on, credential-driven family, not a worm that spreads through a vulnerability. The operator enters through one server with weak RDP credentials, dumps local credentials, uses them to reach other internal hosts, spreads machine by machine, and then runs encryption across the estate at the end.
Spread that wide usually reflects three structural problems: no network segmentation, so one server can reach nearly every host; a single administrator password shared across many machines, which is especially common in healthcare and education networks; and a backup system using the same credentials as production, so backups are encrypted too.
There is an important implication for response: resetting passwords only on encrypted hosts is not enough. Domain administrator and all privileged account passwords must be reset from a clean host, with confirmation that every credential the attacker holds is invalidated, or re-encryption during recovery is very likely.
How do I distinguish GlobeImposter from Crysis/Dharma and Phobos?
All three are common in China and all use brute-forced RDP, but their markers differ clearly:
- GlobeImposter: themed group suffixes (zodiac plus 4444, deity plus 666 — .Dragon4444, .Ares666), a how_to_back_files.html note rendered as a web page, and the base filename usually preserved.
- Crysis/Dharma: filenames rewritten as originalname.id-8 hex chars.[email].suffix (.cezar, .arena, .bip, .combo, .java), with info.hta and FILES ENCRYPTED.txt notes.
- Phobos: filenames rewritten as originalname.id[8 chars-4 digits].[email].suffix (.faust, .elbie, .eking), with info.txt plus info.hta notes.
The distinction drives the recovery path: Phobos has an official free decryptor released by Japan's National Police Agency in July 2025, some early Crysis/Dharma variants are covered by Kaspersky's RakhniDecryptor, and GlobeImposter's 4444/666 series has no tool at all. Hand the notes and a few encrypted samples to a response team and identification usually takes hours.
Our backups were encrypted too — is there anything else?
Yes, but it takes a systematic search. GlobeImposter's reach is bounded by the credentials and paths available to the operator, so these locations are frequently missed and survive:
- Storage outside the credential domain: non-domain backup servers and NAS devices requiring separate authentication.
- Storage-layer snapshots: array- or NAS-native snapshots (some invisible to the encrypting process) and hypervisor snapshots.
- Cloud version history: prior object versions with object lock, plus cloud drive recycle bins and version records.
- Hosts never accessed: servers using standalone local accounts, endpoints powered off at the time, Linux servers.
- Side-channel copies: submitted data, downstream synchronisation databases, read-only replicas, report exports, email attachments, paper archives.
Two technical paths are assessed alongside: structure-level repair of large files (after testing how encryption was applied) and low-level fragment recovery (which requires stopping writes to affected volumes immediately).
We do not promise "100% recovery" — but in most cases a systematic sweep of these sources, combined with repair and log replay, produces noticeably higher coverage than the first impression suggests.
Sources
- Sangfor Farsight Labs: New GlobeImposter Ransomware Variant in Healthcare Industry
- Sangfor Farsight Labs: New GlobeImposter of Olympian Gods 2.0 is coming
- SentinelOne: GlobeImposter Ransomware – Analysis, Detection, and Mitigation
- AhnLab ASEC: GlobeImposter Ransomware Being Distributed with MedusaLocker via RDP
- Emsisoft: GlobeImposter decryptor(仅适用 .crypt 早期变种)
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated