Green Army was an early Chinese patriotic hacking group active from 1997 until its disbandment in 2000. It was among the formative “red hacker” communities that emerged in China in the late 1990s alongside groups such as the Honker Union of China and China Eagle Union. Founded by Gong Wei, also known as goodwell, Green Army reportedly had a small operational team of roughly 40 members despite later claims of approximately 3,000 members. Its broader registered community included many low-barrier forum participants rather than technically capable operators. The group is associated with the nationalist, hacktivist milieu that helped shape China’s subsequent cybersecurity and state-adjacent contractor ecosystem. Wu Haibo, founder of the Chinese hacking contractor I-Soon, was previously a Green Army member. Green Army had ceased operations well before the 2009–2010 Operation Aurora campaign.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chinese patriotic hacker group cited in discussion of the historical evolution and later fragmentation or commercialization of China’s hacker ecosystem. The article states that it had disbanded in 2000.
Chinese 'red hacker' collective active in late 1990s–2000s; large public membership/registrations but a small operational core conducting hacking and support functions (e.g., translators, webmasters, authors).
Early Chinese hacktivist/patriotic hacking scene referenced as an origin point for individuals later involved in contractor hacking; not described with specific contemporary malware/TTPs in this article.
Early Chinese patriotic hacking group involved in internet defacements, DDoS attacks, and credential theft targeting the U.S. and other Chinese adversaries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.