thegreenbloodgroup logo

thegreenbloodgroup

1 incidentes 1 paises 0 sectores ransomware Ultimo: 2026-06-25
Aliases: GreenBlood, Green Blood Virus
Ver en IntelTracker → APTTrail →
The Green Blood Group emerged as a newly active ransomware operation in early 2026, distinguishing itself as a technically competent and professionally engineered threat rather than a rebrand of a legacy group. The group's primary motivation is financial gain through a double-extortion model, leveraging a dedicated Tor-based leak site where victim data is initially withheld and then publicly disclosed to exert negotiation pressure. Their operational strategy includes a unique staged data disclosure, allowing victims a fixed period to negotiate before their identities and stolen information are exposed. The group was active for approximately one month, from January to February 2026.

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

India (1)

Paises objetivo (SOCRadar)

BelgiumColombiaEgyptIndiaSenegal

Sectores objetivo (SOCRadar)

ManufacturingOtherPublic AdministrationNational Security&International AffairsNational Security

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com