GreenSpot
0 incidentes
0 paises
0 sectores
apt TW Ultimo: -
Aliases: APT-Q-20, PoisonVine, apt-c-01, poison ivy
GreenSpot is an advanced persistent threat group, also known by the aliases APT-Q-20 and PoisonVine, that is assessed with high confidence to be of Taiwanese origin. This group has been continuously active since at least 2007, primarily conducting cyberespionage campaigns against entities within mainland China. Their principal motivation is data theft, specifically targeting confidential documents, political and military intelligence, and login credentials. GreenSpot distinguishes itself through its sustained, long-term operations spanning over a decade, its consistent targeting of Chinese government, academic, and military sectors, and its adeptness at modifying open-source tools and exploiting existing vulnerabilities, including an early adoption of the MHT format for CVE-2012-0158 exploitation to bypass antivirus software. The group has also been observed creating convincing spoofed domains and fake download pages to facilitate credential theft.
Sectores objetivo (SOCRadar)
Educational ServicesPublic AdministrationSpace & DefenseNational Security&International Affairs