Also known as: tracked as, Butler Spider, Abyss, Broomstick, CleanUp, Seedworm, is using trusted software, DLL side-loading, aviation, finance, education, government, public sector
The Green Blood Group has emerged as a sophisticated threat actor that blends classic social engineering with cutting‑edge exploitation techniques. They routinely acquire access to critical infrastructure by leveraging outdated firmware (FortiWeb CVE‑2025‑55182) and privileged cloud management tools (HPE OneView CVE‑2025‑37164), allowing them to pivot into deeper network layers. Once inside, the group injects malicious DLLs through fake svchost binaries and deploys web shells such as China Chopper, ensuring persistence and lateral movement. A hallmark of their operations is the use of encrypted Cobalt Strike beacons downloaded from domains m\.fasterxml\.org and fasterxml\.org, which facilitate stealthy command and control. Their attack chains routinely incorporate phishing campaigns featuring spoofed Booking.com emails and BSOD‑spoofing screens to harvest credentials, especially from improperly secured cloud accounts lacking MFA. After establishing footholds, the group typically installs its proprietary ransomware (Green Blood v1/v2) and orchestrates large‑scale data exfiltration. Data is often exfiltrated via Tor‑based leak sites, with evidence of AI‑driven steganographic techniques (Tuoni malware) used to cloak transmitted payloads. Recent incidents against a Senegalese governmental identity system demonstrated the organization’s ability to decrypt 139 TB of sensitive material and disseminate it publicly. Overall, the Green Blood Group demonstrates a highly coordinated approach that blends exploit use, social engineering, sophisticated tooling, and data‑centric monetization strategies.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The Green Blood Group is a medium‑sophistication criminal organization whose primary motive is financial gain through ransomware and large‑scale data exfiltration, targeting critical sectors such as government, finance, telecommunications, and aviation across the Middle East and West Africa. Using social engineering, zero‑day exploits like FortiWeb CVE‑2025‑55182 and HPE OneView CVE‑2025‑37164, and advanced malware including Cobalt Strike beacons and AI‑steganographic tools, they execute multi‑phase attacks that culminate in encrypted data and widespread ransomware deployment.
Goals & Targeting
The group’s strategic objective is primarily financial gain through ransomware payouts and data exfiltration. Target selection focuses on organizations with high-value data in government, finance, telecommunications, defense, healthcare, manufacturing, critical infrastructure, aviation, hospitality, and gaming sectors, especially where legacy systems or insecure cloud migrations increase vulnerability. The actor leverages opportunistic exposures such as misconfigured cloud services to harvest credentials, then exploits zero‑days to gain elevated privileges, eventually executing ransomware and exfiltrating data to leverage for ransom or blackmail.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Green Blood Group has demonstrated a pattern of targeted, multi‑phase campaigns that begin with exploitation of known vulnerabilities in critical infrastructure and culminate in ransomware deployment accompanied by massive data exfiltration. A notable operation against the Senegalese government’s identity card system spanned roughly one month in early 2026, resulting in the theft of ~139 TB of sensitive data that was publicly released via a Tor‑based leak site. These campaigns display high operational precision, including AI‑driven steganographic exfiltration and rapid pivoting through Fast Reverse Proxy. While currently only a few public cases exist, analysts expect similar tactics to recur across other sectors with poorly patched devices or misconfigured cloud environments.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate to high confidence in the technical indicators and documented attack incidents (e.g., Senegalese government operation), corroborated by multiple independent sources. However, publicly available detail on the full breadth of tools, internal supply chains, and future campaign scope remains limited; ongoing monitoring and analysis are required to fill these gaps.
No campaigns linked yet.
No observed data linked yet.
8
Techniques
51
Tools
0
Campaigns
37
IOCs
0
Observed Data
5
Tactics