GreenBot is a cloud- and web-focused malware or hacktool family referenced alongside AlienFox, Legion, Predator, and Androxgh0st-derived tooling. The provided content indicates that GreenBot shares code from the Androxgh0st credential-scraping module and has considerable overlap with other publicly available toolsets that repurpose Androxgh0st and GreenBot modules for their own variants. Other researchers have also summarized some of the same scripts as Androxgh0st and GreenBot, with GreenBot additionally referred to as "Maintance." High-confidence details in the content do not provide a standalone technical breakdown of GreenBot’s full feature set, but the surrounding context places it within a cluster of Python-based cloud attack tools used to harvest credentials and secrets from exposed web application configuration files and to abuse cloud and SaaS services. Related overlapping toolsets in this cluster target services such as AWS SES, Office 365, Twilio, SendGrid, and common CMS or web frameworks including Laravel, Drupal, Joomla, Magento, OpenCart, PrestaShop, and WordPress. No GreenBot-specific indicators of compromise beyond the name and alias relationship are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cloud-focused malware family mentioned as sharing credential scraping code from Androxgh0st.
Referenced as a malware family name used by other researchers for related open-source scripts in the same ecosystem; the content gives no separate technical profile beyond the surrounding credential theft and cloud service abuse context.
A named module/tool whose code is reused by Predator-related cloud attack toolsets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.