Uptime Hamster: 10d 11h 38mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza GreenSpot

GreenSpot

0 incidentes 0 paises 0 sectores apt TW Ultimo: -
Aliases: APT-Q-20, PoisonVine, apt-c-01, poison ivy
Ver en IntelTracker → APTTrail →
GreenSpot is an advanced persistent threat group, also known by the aliases APT-Q-20 and PoisonVine, that is assessed with high confidence to be of Taiwanese origin. This group has been continuously active since at least 2007, primarily conducting cyberespionage campaigns against entities within mainland China. Their principal motivation is data theft, specifically targeting confidential documents, political and military intelligence, and login credentials. GreenSpot distinguishes itself through its sustained, long-term operations spanning over a decade, its consistent targeting of Chinese government, academic, and military sectors, and its adeptness at modifying open-source tools and exploiting existing vulnerabilities, including an early adoption of the MHT format for CVE-2012-0158 exploitation to bypass antivirus software. The group has also been observed creating convincing spoofed domains and fake download pages to facilitate credential theft.

Aliases del actor

APT-Q-20PoisonVineapt-c-01poison ivy

Actores similares

apt-poisonneedlesactor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1apt-38actor · 1
Tipo
apt
Pais origen
TW
Motivacion
-
Impacto
16
Actualizado
Sat, 17 Ma

Sectores objetivo (SOCRadar)

Educational ServicesPublic AdministrationSpace & DefenseNational Security&International Affairs