thegreenbloodgroup
1 incidentes
1 paises
0 sectores
ransomware Ultimo: 2026-06-25
Aliases: GreenBlood, Green Blood Virus
The Green Blood Group emerged as a newly active ransomware operation in early 2026, distinguishing itself as a technically competent and professionally engineered threat rather than a rebrand of a legacy group. The group's primary motivation is financial gain through a double-extortion model, leveraging a dedicated Tor-based leak site where victim data is initially withheld and then publicly disclosed to exert negotiation pressure. Their operational strategy includes a unique staged data disclosure, allowing victims a fixed period to negotiate before their identities and stolen information are exposed. The group was active for approximately one month, from January to February 2026.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
Belgium
Colombia
Egypt
India
Senegal
Sectores objetivo (SOCRadar)
ManufacturingOtherPublic AdministrationNational Security&International AffairsNational Security
URLs nuevas detectadas en IntelTracker