GreenSpot is a long-running espionage-focused advanced persistent threat cluster assessed to have operated for many years, with activity possibly dating back to around 2007 and clearer campaign continuity from 2011 through at least 2017. The actor has been associated with a Taiwan-linked source direction and is known for targeting Chinese government entities as well as aviation-, military-, and research-related organizations. Known aliases include GreenSpot, greenspot_apt, and 绿斑. GreenSpot’s operations have centered on spearphishing for initial access, typically using malicious attachments delivered as either trojanized executables or exploit documents. The group repeatedly relied on older or 1-day vulnerabilities rather than exclusive zero-days, including documented use of CVE-2012-0158, CVE-2014-4114, and later CVE-2017-8759. A notable tradecraft characteristic was early use of MHT-formatted CVE-2012-0158 lure documents to reduce antivirus detection while presenting decoy content to victims. The actor consistently used modified public malware and customized loaders for defense evasion, persistence, and post-compromise collection. Malware associated with GreenSpot includes Poison Ivy, Gh0st, HttpBots, and customized ZXShell variants. These customized ZXShell samples expanded standard functionality with targeted document theft, credential collection, host and network reconnaissance, and selective harvesting of files relevant to military and aviation themes. Earlier tooling linked to the same source direction also included utilities for remote shell access, administration, keylogging, persistence, local monitoring, and file packaging for exfiltration. GreenSpot demonstrated practical but effective post-exploitation tradecraft. Observed capabilities include persistence, credential theft, keylogging, reconnaissance, exfiltration, and use of staged loaders that decrypt and execute shellcode in memory. In later campaigns, the actor used multi-stage infection chains involving script-based downloaders and shellcode loaders culminating in deployment of Poison Ivy. Campaign linkage has been supported by overlapping infrastructure, shared operational patterns, common passwords, similar loaders, and code similarities across incidents. Overall, GreenSpot is best characterized as a persistent cyber-espionage actor that favored repeatable phishing, exploit reuse, and tailored customization of commodity malware to steal sensitive documents and intelligence from Chinese state, defense, aviation, and research targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
另一种是格式攻击文档,利用漏洞CVE-2012-0158来释放并执行可执行文件,同时打开欺骗收件人的“正常”文档文件。... CVE-2012-0158是一个文档格式溢出漏洞... 该组织则使用了MHT格式,这种格式同样可以触发漏洞,而且在当时一段时间内可以躲避多种杀毒软件的查杀。
我们有一定的分析证据表明,“绿斑”组织在2014年10月前曾使用CVE-2014-4114漏洞。这可能表示该组织与地下漏洞交易有相应的渠道联系。
安天2017年针对“绿斑”组织的一个新的前导攻击文档进行了分析,该文档利用最新的CVE-2017-8759漏洞下载恶意代码到目标主机执行。样本采用RTF格式而非之前的宏代码方式,在无须用户交互的情况下就可以直接下载并执行远程文件,攻击效果更好。
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as conducting phishing campaigns using fake 163.com login pages.
Long-running espionage-focused APT activity targeting Chinese government departments and aviation, military, and research-related institutions using spear-phishing emails, malicious Office/MHT documents, bundled executables, and multiple RAT families for persistence, remote control, and document theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.