Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors the green blood group

the green blood group

TLP:CLEAR
Active

Also known as: tracked as, Butler Spider, Abyss, Broomstick, CleanUp, Seedworm, is using trusted software, DLL side-loading, aviation, finance, education, government, public sector

Description

The Green Blood Group has emerged as a sophisticated threat actor that blends classic social engineering with cutting‑edge exploitation techniques. They routinely acquire access to critical infrastructure by leveraging outdated firmware (FortiWeb CVE‑2025‑55182) and privileged cloud management tools (HPE OneView CVE‑2025‑37164), allowing them to pivot into deeper network layers. Once inside, the group injects malicious DLLs through fake svchost binaries and deploys web shells such as China Chopper, ensuring persistence and lateral movement. A hallmark of their operations is the use of encrypted Cobalt Strike beacons downloaded from domains m\.fasterxml\.org and fasterxml\.org, which facilitate stealthy command and control. Their attack chains routinely incorporate phishing campaigns featuring spoofed Booking.com emails and BSOD‑spoofing screens to harvest credentials, especially from improperly secured cloud accounts lacking MFA. After establishing footholds, the group typically installs its proprietary ransomware (Green Blood v1/v2) and orchestrates large‑scale data exfiltration. Data is often exfiltrated via Tor‑based leak sites, with evidence of AI‑driven steganographic techniques (Tuoni malware) used to cloak transmitted payloads. Recent incidents against a Senegalese governmental identity system demonstrated the organization’s ability to decrypt 139 TB of sensitive material and disseminate it publicly. Overall, the Green Blood Group demonstrates a highly coordinated approach that blends exploit use, social engineering, sophisticated tooling, and data‑centric monetization strategies.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Government
Telecommunications
Defense
Financial services
Education
Healthcare
Manufacturing
Critical infrastructure
Aviation
Hospitality
Gaming

Targeted Countries / Regions

NG
IR
KP
US
IN
EG

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

The Green Blood Group is a medium‑sophistication criminal organization whose primary motive is financial gain through ransomware and large‑scale data exfiltration, targeting critical sectors such as government, finance, telecommunications, and aviation across the Middle East and West Africa. Using social engineering, zero‑day exploits like FortiWeb CVE‑2025‑55182 and HPE OneView CVE‑2025‑37164, and advanced malware including Cobalt Strike beacons and AI‑steganographic tools, they execute multi‑phase attacks that culminate in encrypted data and widespread ransomware deployment.

Goals & Targeting

The group’s strategic objective is primarily financial gain through ransomware payouts and data exfiltration. Target selection focuses on organizations with high-value data in government, finance, telecommunications, defense, healthcare, manufacturing, critical infrastructure, aviation, hospitality, and gaming sectors, especially where legacy systems or insecure cloud migrations increase vulnerability. The actor leverages opportunistic exposures such as misconfigured cloud services to harvest credentials, then exploits zero‑days to gain elevated privileges, eventually executing ransomware and exfiltrating data to leverage for ransom or blackmail.

Enhanced Description

Key Capabilities

  • Deploy encrypted Cobalt Strike beacon payloads fetched from domains m\.fasterxml\.org and fasterxml\.org
  • Use DLL side‑loading via malicious svchosts.exe on Windows and deploy macOS update payloads
  • Exploit FortiWeb CVE-2025-55182 (React2Shell) to gain initial access to web applications
  • Employ Fast Reverse Proxy as a pivot tool for internal network reconnaissance and exfiltration
  • Conduct social–engineering attacks through phishing emails, BSOD spoofing screens, and credential collection from unprotected cloud accounts
  • Exploit HPE OneView CVE-2025-37164 to achieve full infrastructure control
  • Deploy China Chopper web shells and Samurai-backdoor for persistence and lateral movement
  • Use AI‑driven steganography (Tuoni malware) for covert data exfiltration
  • Encrypt victim files with Green Blood Group ransomware v1/v2 while exfiltrating large volumes of data via Tor leak sites

MITRE ATT&CK Tactics

Initial Access
Execution
Command & Control
Defense Evasion
Persistence
Privilege Escalation
Credential Access
Exfiltration
Impact

ATT&CK Techniques

T1105
T1190
T1071
T1574.002
T1566.002
T1505.004
T1203
T1027.6

Software / Tooling

Cobalt Strike
Fast Reverse Proxy
React2Shell
ClickFix
Tuoni-malware
China Chopper web shell
Samurai-backdoor
HPE OneView CVE-2025‑37164 exploit
Green Blood Group Ransomware v1/v2

Campaigns & Victims

The Green Blood Group has demonstrated a pattern of targeted, multi‑phase campaigns that begin with exploitation of known vulnerabilities in critical infrastructure and culminate in ransomware deployment accompanied by massive data exfiltration. A notable operation against the Senegalese government’s identity card system spanned roughly one month in early 2026, resulting in the theft of ~139 TB of sensitive data that was publicly released via a Tor‑based leak site. These campaigns display high operational precision, including AI‑driven steganographic exfiltration and rapid pivoting through Fast Reverse Proxy. While currently only a few public cases exist, analysts expect similar tactics to recur across other sectors with poorly patched devices or misconfigured cloud environments.

IOC Patterns

  • Domains m\.fasterxml\.org and fasterxml\.org used for downloading malicious payloads
  • Malicious svchosts.exe execution on Windows endpoints
  • CVE-2025-55182 (FortiWeb React2Shell) exploitation indicator
  • Phishing emails spoofing Booking.com URL and content
  • BSOD spoofing screens to trick users into installing malware
  • China Chopper web shell installation files
  • Samurai-backdoor deployment scripts
  • Green Blood Group ransomware encryptor v1/v2 binary
  • Tor-based data leak site hosting exfiltrated payloads
  • AI‑steganographic artifacts identified in Tuoni malware

Recommended Actions

  • Conduct comprehensive risk assessments before migrating to cloud environments and enforce strict security controls during migration
  • Block or sandbox downloads from untrusted domains such as m\.fasterxml\.org and fasterxml\.org
  • Patch FortiWeb devices to latest firmware to mitigate CVE-2025-55182 vulnerabilities
  • Deploy monitoring for DLL side‑loading patterns like svchosts.exe on Windows endpoints
  • Implement network segmentation and monitor traffic to detect and block Fast Reverse Proxy activity
  • Enforce multi‑factor authentication for all cloud accounts
  • Promptly patch HPE OneView to fix CVE-2025-37164
  • Train staff to recognize phishing emails and BSOD spoofing lures
  • Use endpoint detection and response tools to identify web shells and backdoors
  • Block or quarantine known malicious domains, IPs, and Tor exit nodes linked with Green Blood Group
  • Implement strict egress filtering to limit ransomware spread
  • Monitor for AI‑based steganographic malware indicators and suspicious file obfuscation

Suggested Tags

ransomware
Cobalt Strike
DLL-side loading
FortiWeb exploit
React2Shell
cloud migration risk
social engineering
phishing
BSOD spoofing
credential theft
web shell
backdoor
exploit
CVE-2025‑37164
HPE OneView
AI steganography
data exfiltration
Tor data leak site
MFA bypass
Green Blood Group

Confidence Assessment

Moderate to high confidence in the technical indicators and documented attack incidents (e.g., Senegalese government operation), corroborated by multiple independent sources. However, publicly available detail on the full breadth of tools, internal supply chains, and future campaign scope remains limited; ongoing monitoring and analysis are required to fill these gaps.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Email Address 2 Domain 12 Filename 3 IPv4 Address 2 MD5 Hash 1

References

  1. www.watchguard.com — Cited by web research for: Seedworm
  2. www.ccinfo.nl — Cited by web research for: Dark
  3. www.watchguard.com — Cited by web research for: Unknown
  4. www.comparitech.com — Cited by web research for: Education
  5. https://www.rfi.fr/en/africa/202605 — Cited by AI analysis.
  6. https://www.rfi.fr/en/africa/20260515-as-africa-rapidly-goes-digital-it-becomes-a-prime-ta — Cited by AI analysis.
  7. https://foresiet.com/blog/reverse-engineering-green-blood-ransomware/ — Cited by AI analysis.

Intel Summary

8

Techniques

51

Tools

0

Campaigns

37

IOCs

0

Observed Data

5

Tactics

Tags

ransomware
Cobalt Strike
DLL-side loading
FortiWeb exploit
React2Shell
cloud migration risk
social engineering
phishing
BSOD spoofing
credential theft
web shell
backdoor
exploit
CVE-2025‑37164
HPE OneView
AI steganography
data exfiltration
Tor data leak site
MFA bypass
Green Blood Group

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
North Korea (KP)
Confidence
80%
Added
Jul 19, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.