Uptime Hamster: 10d 9h 49mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza thegreenbloodgroup

thegreenbloodgroup

2 incidentes 1 paises 0 sectores ransomware Ultimo: 2026-06-29
Aliases: GreenBlood, Green Blood Virus
Ver en IntelTracker → APTTrail →
The Green Blood Group emerged as a newly active ransomware operation in early 2026, distinguishing itself as a technically competent and professionally engineered threat rather than a rebrand of a legacy group. The group's primary motivation is financial gain through a double-extortion model, leveraging a dedicated Tor-based leak site where victim data is initially withheld and then publicly disclosed to exert negotiation pressure. Their operational strategy includes a unique staged data disclosure, allowing victims a fixed period to negotiate before their identities and stolen information are exposed. The group was active for approximately one month, from January to February 2026.

Aliases del actor

GreenBloodGreen Blood Virus

Actores similares

the-green-blood-groupactor · 2apt-bloodywolfactor · 1greenbugactor · 1GreenSpotapt · 0Bloody Wolfapt · 0GreenCharlieapt · 0GOLD EVERGREENapt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknownscbrksw5fgjtujc2ah42roo6bij2unr2tggfcynpbql5a7yp3s22taid.onionthegreenbloodgroup
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: thegreenbloodgroup
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

India (2)

Paises objetivo (SOCRadar)

BelgiumColombiaEgyptIndiaSenegal

Sectores objetivo (SOCRadar)

ManufacturingOtherPublic AdministrationNational Security&International AffairsNational Security

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com