The Green Blood Group is a ransomware operator currently active on public leak sites. Darkfield has indexed 2 public victims claimed by this operator between February 4, 2026. The Green Blood Group is a ransomware threat actor first observed in February 2026 with an apparent financial motivation, having claimed responsibility for attacks against a very limited number of victims to date. As of the time of this writing, no reputable threat intelligence sources including CISA, FBI, Mandiant, or comparable research organizations have published detailed technical attribution or comprehensive operational profiles for this group, indicating it remains an emerging and obscure actor in the ransomware landscape. Based on available victim data, the group has targeted organizations in Egypt and Senegal, with a focus on the manufacturing and public sector verticals, suggesting a possible interest in operationally critical or government-adjacent targets in the African region. With only two known victims documented, the group's attack methodology, tooling, initial access vectors, encryption implementation, and extortion tactics remain largely uncharacterized in open-source intelligence, and it is unclear whether the group operates as a Ransomware-as-a-Service platform or functions as a closed, independent operation. Given its recent emergence and low victim count, The Green Blood Group should be monitored as a developing threat, particularly by organizations operating in manufacturing and public sector roles across North and West Africa, though definitive technical indicators and behavioral patterns await further documentation by the security research community.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.