Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors thegreenbloodgroup

thegreenbloodgroup

TLP:CLEAR
Active

Description

The Green Blood Group is an emerging ransomware operation first identified in early 2026 whose Go-based Windows payload uses ChaCha8 encryption and aggressively destroys backup and recovery options, targeting organizations in India, Senegal, Egypt, Colombia, and Belgium.

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The Green Blood Group (aka TheGreenBlood) is an emerging ransomware operation identified in early 2026. Primarily targeting organizations in India, Senegal, Egypt, Colombia, and Belgium, the group employs a Go-based Windows payload utilizing ChaCha8 encryption and destructive backup deletion techniques. Unlike many ransomware groups, they exhibit medium sophistication with a focus on financial gain through organizational disruption.

Goals & Targeting

The Green Blood Group's strategic objectives align closely with typical ransomware operations, focusing on disrupting business continuity to coerce victims into paying ransoms for decrypted data. Their targeting strategy appears geographically diverse but may reflect a broader focus on sectors or regions where defensive measures are weaker or backup systems are less mature. The group's activities so far suggest an early-stage operation that is still establishing its campaign patterns and victimology.

Enhanced Description

The Green Blood Group (thegreenbloodgroup) is a newly emerged cybercriminal entity specializing in ransomware attacks. Their operations were first observed in early 2026 and are characterized by the use of a Go-based payload that leverages ChaCha8 encryption algorithm. This group has demonstrated a particular focus on targeting organizations in diverse geographies, including India, Senegal, Egypt, Colombia, and Belgium. Their unique modus operandi involves not only encrypting victim data but also aggressively destroying backup and recovery options, which significantly complicates incident response and increases the likelihood of successful ransoms. The group's operational profile suggests a medium level of sophistication, with an emphasis on financial gain through organizational disruption.

Key Capabilities

  • Go-based ransomware payload
  • ChaCha8 encryption implementation
  • Backup file destruction techniques
  • Laterally moving within networks

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1059.003
T1055
T1486
T1566.001

Software / Tooling

Ransomwarepayload-Go-based ChaCha8 variant
Phishing Tools
Network Lateral Movement Tools

Campaigns & Victims

The Green Blood Group appears to be an emerging actor with limited operational history as of February 2026. Their campaigns demonstrate a focus on specific geographic regions, suggesting an initial targeting strategy based on either opportunity or organizational maturity in those areas. The group's use of aggressive backup destruction indicates a sophisticated approach for disrupting recovery efforts. Notable past operations include targeted ransomware attacks against education, healthcare, and small to medium enterprises (SMEs) in the identified countries.

IOC Patterns

  • Spear-phishing with email-based campaigns
  • Use of OnionMail domains for C2 communications
  • Go-based payload distribution via malicious attachments

Recommended Actions

  • Implement advanced phishing detection solutions
  • Monitor for suspicious emails from domains like onionmail.org
  • Regularly backup critical systems and isolate backup data
  • Enforce multi-factor authentication (MFA) on RDP and network access points

Suggested Tags

Ransomware
Financial-Gain
Criminal
Emerging-THREAT
India
Senegal

Confidence Assessment

Medium confidence in the accuracy of this intelligence due to limited operational history and newly observed behavior. Data gaps include detailed TTP analysis, long-term campaign patterns, and specific tools/malware used beyond the Go-based payload.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial-Gain
Criminal
Emerging-THREAT
India
Senegal

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Feb 4, 2026
Last Seen
Feb 4, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.