GreenCube is an espionage threat actor also known as UNC3707. In the provided content, GreenCube is identified as one of several groups that have exploited some of the same webmail vulnerabilities discussed in ESET’s reporting, and as one of the espionage groups that have targeted webmail servers such as Roundcube and Zimbra. The content does not provide further high-confidence details on GreenCube’s attribution, sub-groups, specific malware, or broader operations beyond this webmail-focused activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an espionage group targeting webmail servers (e.g., Roundcube and Zimbra) for email theft.
Named espionage group referenced as also exploiting webmail XSS vulnerabilities similar to those used in Operation RoundPress.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.