Uptime Hamster: 10d 11h 34mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza GreenCharlie

GreenCharlie

0 incidentes 0 paises 0 sectores apt IR Ultimo: -
Ver en IntelTracker → APTTrail →
GreenCharlie is an Iran-nexus state-sponsored advanced persistent threat group, active since at least 2020, primarily conducting cyber espionage operations for information theft and influence. The group is associated with the Islamic Revolutionary Guard Corps (IRGC) and overlaps with other Iranian threat actors including Mint Sandstorm, Charming Kitten, APT42, Magic Hound, APT 35, Cobalt Illusion, Damselfly, TA453, and Yellow Garuda. GreenCharlie distinguishes itself through the heavy and evolving use of dynamic DNS domains for its phishing infrastructure, the deployment of a multi-stage PowerShell-based malware family (GORBLE, POWERSTAR, and TAMECAT), and its consistent leveraging of VPN services and privacy tools like ProtonVPN and ProtonMail to obfuscate operational traffic.
Motivacion