GreenBlood is a low-prevalence ransomware strain first observed in late January 2026 with continued activity reported in March 2026. It encrypts victim data using AES and RSA, with the ransom note also claiming AES-256-based encryption, and then demands payment for decryption. Reported sample filenames include green.exe and sql_update.exe. After encryption, it appends the .tgbg extension to affected files and drops a ransom note named !!!READ_ME_TO_RECOVER_FILES!!!.txt. The note attributes the operation to “TH3 GR33N BL00D GROUP” / “THE GREEN BLOOD GROUP,” includes a Recovery ID and Machine ID, instructs victims to pay in Bitcoin, and provides contact channels via thegreenblood@proton.me and the Tor onion service scbrksw5fgjtujc2ah42roo6bij2unr2tggfcynpbql5a7yp3s22taid[.]onion:8000. Reported targeting is oriented toward English-speaking users, though distribution may be global. Mentioned victim file categories include documents, databases, photos, music, videos, disk images, and archives, with likely affected locations including the Desktop, user folders, and %TEMP%. Reported infection and distribution vectors include insecure RDP, email spam, malicious attachments, deceptive downloads, botnets, exploits, malvertising, web injects, fake updates, and repacked installers. Detection names cited in the source include DrWeb Trojan.Encoder.44290, ESET WinGo/Filecoder.GreenBlood.A, Kaspersky Trojan-Ransom.Win32.Encoder.afyu, Microsoft Ransom:Win32/Avaddon.P!MSR, and TrendMicro Ransom.Win32.ABBADON.USBLAU26. Reported sample hashes are MD5 e760729dcee518659d9510ae1705db51, SHA-1 f0336d1dad9615f3227bf7750d1cdfd3efa10008, and SHA-256 12bba7161d07efcb1b14d30054901ac9ffe5202972437b0c47c88d71e45c7176.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GreenBlood Ransomware ... Этот крипто-вымогатель шифрует данные пользователей с помощью комбинации алгоритмов AES+RSA, а затем требует выкуп, чтобы вернуть файлы.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
New ransomware strain/group mentioned as starting operations this year; noted as the group that hit Senegal government networks.
Ransomware that encrypts user data using AES+RSA, appends the .tgbg extension, drops the ransom note !!!READ_ME_TO_RECOVER_FILES!!!.txt, and demands Bitcoin payment for decryption. The content says it may spread via insecure RDP configuration, email spam, malicious attachments, deceptive downloads, botnets, exploits, malvertising, web injects, fake updates, and repacked infected installers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.