Skip to main content
Mallory
1 malware family

绿斑

Also known as绿斑

绿斑 is an APT threat actor tracked by Antiy Emergency Response Center and assessed in the provided reporting as linked to authorities in Taiwan. Antiy states it observed the group conducting attacks in the second half of 2024 against specific industry targets in China, with the apparent objectives of persistent access, long-term host control, lateral movement, and information theft. Antiy also states it had previously reported on 绿斑 in September 2018 and assessed the group’s activity as dating back to 2007. In the described campaign, 绿斑 used spear-phishing emails sent from official-looking accounts to lure victims to a malicious website impersonating a government information disclosure page. The site redirected victims to download a decoy file presented as a PDF but actually a C# EXE downloader. The downloader retrieved an encrypted payload disguised as an MP4/MOV file, decrypted it with AES using fixed key and IV values, decompressed it with GZip, and executed it in memory using delegate and unmanaged-code techniques. The payload included anti-debugging functionality. Antiy assessed the final payload to be generated by the open-source Sliver C2 framework, citing code similarity and a matching TLS JA3 fingerprint (19e29534fd49dd27d09234e639c4057e). The reporting maps the activity to 25 MITRE ATT&CK techniques across 10 stages, including reconnaissance, resource development, initial access, execution, defense evasion, discovery, collection, command-and-control, exfiltration, and impact. Known alias information in the provided content only includes 绿斑.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics31 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1589
Gather Victim Identity Information
TA0042
Resource Development
3 techniques
T1583
Acquire Infrastructure
T1585
Establish Accounts
T1587
Develop Capabilities
TA0001
Initial Access
2 techniques
T1189
Drive-by Compromise
T1566
Phishing
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
TA0002
Execution
1 technique
T1204
User Execution
TA0005
Stealth
5 techniques
T1027
Obfuscated Files or Information
T1036
Masquerading
T1140
Deobfuscate/Decode Files or Information
T1497
Virtualization/Sandbox Evasion
T1497.001
System Checks
T1620
Reflective Code Loading
TA0006
Credential Access
1 technique
T1056
Input Capture
TA0007
Discovery
9 techniques
T1016
System Network Configuration Discovery
T1018
Remote System Discovery
T1046
Network Service Discovery
T1057
Process Discovery
T1069
Permission Groups Discovery
T1082
System Information Discovery
T1083
File and Directory Discovery
T1087
Account Discovery
T1497
Virtualization/Sandbox Evasion
T1497.001
System Checks
TA0009
Collection
2 techniques
T1056
Input Capture
T1113
Screen Capture
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1573
Encrypted Channel
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping26

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.