绿斑 is an advanced persistent threat group assessed to be linked to authorities in Taiwan and active since at least 2007. The group has been associated with long-running espionage-oriented intrusions against specific industry targets in China, with objectives centered on persistent access, long-term host control, lateral movement, and theft of information. The group commonly uses spear-phishing for initial access, including emails crafted to appear as if sent from official or trusted accounts. Victims are lured to spoofed government-themed web pages and induced to download decoy documents that are in fact malware loaders. Observed tooling includes a C# downloader disguised as a document, followed by retrieval of an encrypted secondary payload masquerading as benign media content. The malware chain uses AES decryption, GZip decompression, and in-memory execution through delegated and unmanaged code techniques, reflecting a strong emphasis on defense evasion and post-compromise stealth. Anti-debugging functionality has also been observed. Post-exploitation activity has been linked to the Sliver command-and-control framework, indicating use of open-source offensive tooling for command and control, persistence, lateral movement, and exfiltration. Reported ATT&CK coverage spans reconnaissance, resource development, initial access, execution, defense evasion, discovery, collection, command and control, exfiltration, and impact. The actor is known primarily by the name 绿斑.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.