Skip to main content
Mallory
4 malware families

UNK_GreenSec

Also known asunk_greensec

UNK_GreenSec is a threat cluster linked to TransferLoader malware and associated ransomware deployment. Reporting cited in the content describes the cluster as involved in ongoing malware campaigns and, in one mention context, as Russia-attributed or Russia-linked, though some campaign-level attribution remains low confidence. Researchers and reporting noted highly similar infrastructure and tradecraft overlaps between UNK_GreenSec and the Russia-linked operation TA829 (also known as Nebulous Mantis, Storm-0978, UNC2596, and RomCom/Void Rabisu/Tropical Scorpius in related reporting), including use of REM proxy services relaying traffic to newly created freemail accounts, SSH tunnels established with PuTTY PLINK, and IPFS services for utility hosting. Proofpoint assessed that the overlap could indicate a shared third-party infrastructure provider or that the clusters may be the same operation. UNK_GreenSec activity has been tied to TransferLoader, which later launches Morpheus and Metasploit ransomware strains. Separate reporting linked infrastructure used in the ZipLine campaign to UNK_GreenSec; ZipLine targeted supply chain-critical manufacturing and other organizations, especially in the United States, using contact-form initiated social engineering, fake NDA-themed lures, malicious ZIP archives, LNK-triggered PowerShell loaders, COM TypeLib hijacking persistence, and the MixShell backdoor, which used DNS TXT tunneling with HTTP fallback for command and control. Mentioned context also states UNK_GreenSec used NDA-themed lures in August 2025 to deliver the MixShell backdoor. Known alias in the provided content: unk_greensec.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal4

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

UNK_GreenSec | Mallory