Ransomware Group intelligence
The Green Blood Group
InactiveTrack The Green Blood Group with 3 published victims and 2 known leak locations in a single intelligence view.
Overview
The Green Blood Group is tracked by Breach House as a ransomware group with 3 published victims.
Senegal is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | scbrksw5fgjtujc2ah42roo6bij2unr2tggfcynpbql5a7yp3s22taid.onion |
| Leak location 2 | Onion service | Down checked 1h ago | shadowxn303kvvkbjyaoe33emqxrtadijp7xybizbht2thb6x5dvfhad.onion |
Top Activity Sectors (1)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue The Green Blood Group, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: low. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: The Green Blood Group executes malicious payloads via PowerShell scripts injected into engineering workstation environments.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: The Green Blood Group disables Windows security tools like Defender and EDR to prevent rollback or detection on compromised machines.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: The Green Blood Group deletes Volume Shadow Copies and backup directories to eliminate recovery options for victims.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1049 System Network Connections Discovery Discovery
What they do: The Green Blood Group discovers system network connections to identify high-value engineering servers for encryption.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1083 File and Directory Discovery Discovery
What they do: The Green Blood Group uses file and directory discovery to locate sensitive manufacturing and engineering documents for targeting.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1614.001 System Language Discovery Discovery
What they do: The Green Blood Group performs system language discovery to tailor encryption behavior for localized manufacturing environments.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: The Green Blood Group moves laterally across internal networks by exploiting SMB/Windows Admin Shares used in manufacturing infrastructure.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: The Green Blood Group encrypts victim files using its ransomware payload, targeting manufacturing and engineering data specifically.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: The Green Blood Group stops critical engineering services and backup processes via net stop commands to disrupt operations.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: The Green Blood Group inhibits system recovery by corrupting restore points and disabling backup services on affected machines.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
HOW_TO_RECOVER_FILES.txt
##################### TH3 GR33N BL00D GR0UP #################### ----------------- SYSTEM INTRUSION & DATA EXFILTRATION CONFIRMED ------------------- All primary servers, workstations, and backup links within your network have been encrypted and penetrated by THE-GREEN-BLOOD-GROUP. A full copy of TERABYTES of sensitive data has been extracted from your systems. IRREVERSIBLE without our unique decryption key. ################# YOUR DATA IS NOW HELD FOR RANSOM. DO NOT ATTEMPT: ####################### Restarting systems or disconnecting from network. Using third-party decryption or "recovery" tools. Involving external cyber-security firms. Modifying encrypted files or system registry. ANY ATTEMPT WILL CORRUPT DATA PERMANENTLY AND TRIGGER IMMEDIATE DATA LEAK. ####################### DEMAND & RECOVERY PROCESS ########################### To receive the decryption tool and secure the deletion of the stolen dataset, you MUST contact us at the address below within 14 DAYS. To prove the legitimacy of our decryption tool, we decrypt 5-10 non-critical files (each under 20MB). ######################### OUR CONTACTS ####################### SUPPORT EMAIL: [email protected] / [email protected] SUPPORT TOX ID: F97A512AA18917444315510B107AB8B46166CAC4E79DB76B849FFE48A67A4B621AB7CC9A1EFB If Mail Communication channels lost or slow , use TOX EMAIL SUBJECT LINE: [SNIP] - PAYMENT INQUIRY ######################### CONSEQUENCES OF NON-COMPLIANCE ######################### Failure to contact us within 7 DAYS will result in: 14 DAYS : 1% DATASET will be published every next day publicly on multiple dark web leak sites and sent to major media outlets .This includes all client data. You can use the Tor Browser and visit the following link: URL: http://scbrksw5fgjtujc2ah42roo6bij2unr2tggfcynpbql5a7yp3s22taid.onion:8000/ 21 DAYS: If you choose not to contact us, your sensitive data will be published or sold to interested third parties . The dataset will be AUCTIONED to the highest bidder among cybercriminal syndicates and hostile entities. Your clients' financial futures will be sold. ######################## TIME DECREASES WITH EVERY HOUR. ACT NOW. ############################## ------------------------------ END OF COMMUNICATION ------------------------------------------------- - TH3 GR33N BL00D GR0UP
READ_ME_TO_RECOVER_FILES.txt
╔══════════════════════════════════════════════════════════════════════════════╗ ║ YOUR FILES HAVE BEEN ENCRYPTED! ║ ╚══════════════════════════════════════════════════════════════════════════════╝ ##################### TH3 GR33N BL00D GR0UP #################### What happened? --------------- All your important files (documents, photos, databases, etc.) have been encrypted 'enc++' using military-grade AES-256 encryption. Your files are now inaccessible and cannot be recovered without our decryption service. Your unique identifiers: • Recovery ID: GREEN-BLOOD-[SNIP] • Machine ID: [SNIP] • Date/Time: YYYY-MM-DD hh:mm:ss • Files encrypted: .tgbg extension How to recover your files: -------------------------- 1. Contact Us 2. Provide your Recovery ID and Machine ID 3. Follow the payment instructions (Bitcoin only) 4. After payment confirmation, you will receive the decryption tool DO NOT: -------- • Try to decrypt files yourself (you will lose them permanently) • Rename or modify encrypted files • Delete encrypted files • Reinstall Windows or format drives • Use data recovery software Important: ---------- • Payment must be made within 7 days • Price increases every 24 hours • After 21 days, your decryption key will be destroyed • We keep 139 GB of files as proof of decryption capability WARNING: -------- Any attempt to remove this software or recover files without our tool will result in PERMANENT DATA LOSS. This is your only chance to recover your files. Contact Us. ######################### OUR CONTACTS ####################### SUPPORT EMAIL: [email protected] / [email protected] SUPPORT TOX ID: F97A512AA18917444315510B107AB8B46166CAC4E79DB76B849FFE48A67A4B62 1AB7CC9A1EFB If Mail Communication channels lost or slow , use TOX EMAIL SUBJECT LINE: [SNIP] - PAYMENT INQUIRY You can use the Tor Browser and visit the following link: URL: http://scbrksw5fgjtujc2ah42roo6bij2unr2tggfcynpbql5a7yp3s22taid.onion:8000/
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (3)
Search, filter and paginate the victim timeline for The Green Blood Group. Showing 1–3 of 3.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | ECOBAT EGYPT id30681 View details | Egypt | Manufacturing / Engineering | — | |
|
ECOBAT EGYPT operates in the manufacturing and engineering sector in Egypt, providing various services and products. As a key player in the industry, the company's activities are crucial to the country's economy. ECOBAT EGYPT was listed as a ransomware victim associated with The Green Blood Group. |
|||||
| Ransomware | DAF SENEGAL id30682 View details | Senegal | Manufacturing / Engineering | — | |
|
DAF SENEGAL is a company based in Senegal, operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector. DAF SENEGAL was listed as a ransomware victim associated with The Green Blood Group. |
|||||
| Ransomware | DAF SENEGAL id30682 View details | Senegal | Manufacturing / Engineering | — | |
|
Department of Records Automation (DAF) is a Senegalese governmental agency operating under the Ministry of the Interior and Public Security. The agency manages national population databases, issues biometric identity cards (CNI CEDEAO), processes foreign national identity documentation, and maintains other critical civil registration systems. |
|||||