The Green Blood Group is an emerging ransomware operation first identified in early 2026 whose Go-based Windows payload uses ChaCha8 encryption and aggressively destroys backup and recovery options, targeting organizations in India, Senegal, Egypt, Colombia, and Belgium.
Objectives
Executive Summary
The Green Blood Group (aka TheGreenBlood) is an emerging ransomware operation identified in early 2026. Primarily targeting organizations in India, Senegal, Egypt, Colombia, and Belgium, the group employs a Go-based Windows payload utilizing ChaCha8 encryption and destructive backup deletion techniques. Unlike many ransomware groups, they exhibit medium sophistication with a focus on financial gain through organizational disruption.
Goals & Targeting
The Green Blood Group's strategic objectives align closely with typical ransomware operations, focusing on disrupting business continuity to coerce victims into paying ransoms for decrypted data. Their targeting strategy appears geographically diverse but may reflect a broader focus on sectors or regions where defensive measures are weaker or backup systems are less mature. The group's activities so far suggest an early-stage operation that is still establishing its campaign patterns and victimology.
Enhanced Description
The Green Blood Group (thegreenbloodgroup) is a newly emerged cybercriminal entity specializing in ransomware attacks. Their operations were first observed in early 2026 and are characterized by the use of a Go-based payload that leverages ChaCha8 encryption algorithm. This group has demonstrated a particular focus on targeting organizations in diverse geographies, including India, Senegal, Egypt, Colombia, and Belgium. Their unique modus operandi involves not only encrypting victim data but also aggressively destroying backup and recovery options, which significantly complicates incident response and increases the likelihood of successful ransoms. The group's operational profile suggests a medium level of sophistication, with an emphasis on financial gain through organizational disruption.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Green Blood Group appears to be an emerging actor with limited operational history as of February 2026. Their campaigns demonstrate a focus on specific geographic regions, suggesting an initial targeting strategy based on either opportunity or organizational maturity in those areas. The group's use of aggressive backup destruction indicates a sophisticated approach for disrupting recovery efforts. Notable past operations include targeted ransomware attacks against education, healthcare, and small to medium enterprises (SMEs) in the identified countries.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Medium confidence in the accuracy of this intelligence due to limited operational history and newly observed behavior. Data gaps include detailed TTP analysis, long-term campaign patterns, and specific tools/malware used beyond the Go-based payload.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics