Skip to main content

Operator dossier

The Green Blood Group is a ransomware operator currently active on public leak sites. Darkfield has indexed 2 public victims claimed by this operator between February 4, 2026. The Green Blood Group is a ransomware threat actor first observed in February 2026 with an apparent financial motivation, having claimed responsibility for attacks against a very limited number of victims to date. As of the time of this writing, no reputable threat intelligence sources including CISA, FBI, Mandiant, or comparable research organizations have published detailed technical attribution or comprehensive operational profiles for this group, indicating it remains an emerging and obscure actor in the ransomware landscape. Based on available victim data, the group has targeted organizations in Egypt and Senegal, with a focus on the manufacturing and public sector verticals, suggesting a possible interest in operationally critical or government-adjacent targets in the African region. With only two known victims documented, the group's attack methodology, tooling, initial access vectors, encryption implementation, and extortion tactics remain largely uncharacterized in open-source intelligence, and it is unclear whether the group operates as a Ransomware-as-a-Service platform or functions as a closed, independent operation. Given its recent emergence and low victim count, The Green Blood Group should be monitored as a developing threat, particularly by organizations operating in manufacturing and public sector roles across North and West Africa, though definitive technical indicators and behavioral patterns await further documentation by the security research community.

Recent disclosures by The Green Blood Group

All 2 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for The Green Blood Group

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Active ransomware operator

All groups

The Green Blood Group

2 victims indexed · first seen 6 months ago · last activity 6 months ago

2
Victims indexed
#304 of 369 tracked operators
<1m
Active period
Feb 2026 → Feb 2026
Countries hit

At a glance

Status
active
First seen
6 months ago
Last activity
6 months ago

About

The Green Blood Group is a ransomware threat actor first observed in February 2026 with an apparent financial motivation, having claimed responsibility for attacks against a very limited number of victims to date. As of the time of this writing, no reputable threat intelligence sources including CISA, FBI, Mandiant, or comparable research organizations have published detailed technical attribution or comprehensive operational profiles for this group, indicating it remains an emerging and obscure actor in the ransomware landscape. Based on available victim data, the group has targeted organizations in Egypt and Senegal, with a focus on the manufacturing and public sector verticals, suggesting a possible interest in operationally critical or government-adjacent targets in the African region. With only two known victims documented, the group's attack methodology, tooling, initial access vectors, encryption implementation, and extortion tactics remain largely uncharacterized in open-source intelligence, and it is unclear whether the group operates as a Ransomware-as-a-Service platform or functions as a closed, independent operation. Given its recent emergence and low victim count, The Green Blood Group should be monitored as a developing threat, particularly by organizations operating in manufacturing and public sector roles across North and West Africa, though definitive technical indicators and behavioral patterns await further documentation by the security research community.

References

1 link

External sources curated by the MISP threat-intel community.

Recent victims

Loading…

Source

Updated 6 months ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time The Green Blood Group posts a victim.

Add The Green Blood Group to your watchlist — Pro pings you within 5 minutes of any new The Green Blood Group leak-site post, Telegram callout, or affiliate-rebrand inference.