Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

GREENBLOOD

159
Global rank
150 infographic chevron month
Month rank
198 infographic chevron week
Week rank

GREENBLOOD is a Go-based ransomware that uses concurrent ChaCha8 encryption to lock entire Windows environments in under a minute while systematically destroying backups, disabling defenses, and threatening double extortion through a Tor-based data leak site.

Ransomware
Type
Unknown
Origin
1 February, 2026
First seen
29 September, 2026
Last seen

How to analyze GREENBLOOD with ANY.RUN

Type
Unknown
Origin
1 February, 2026
First seen
29 September, 2026
Last seen

IOCs

IP addresses
135.233.95.135
52.110.17.15
138.113.69.36
40.126.31.128
95.100.102.9
2.16.164.104
48.209.138.168
2.16.168.44
48.209.6.48
184.31.95.119
52.109.136.6
2.16.241.207
48.209.133.15
4.207.44.73
23.11.40.157
95.100.102.101
172.211.123.248
52.111.232.11
52.123.224.74
204.79.197.203
Hashes
bbe0867984fd439067703f307018f96ea37fda8f8b79fc12843d6068e77dcc32
9d908ecfb6b256def8b49a7c504e6c889c4b0e41fe6ce3e01863dd7b61a20aa0
4fe7b59af6de3b665b67788cc2f99892ab827efae3a467342b3bb4e3bc8e5bfe
e7e7ba7c94c2574ab9e0d47a90f4660dd0b83d4a935141568c8bfc1024ec87cb
79adab38bd93e2f14609db60ad34a2165e5ae868556f862c4569ae3d8a81a35e
bbfa41253ad301a1cd9c7f6321bff365068178f26cd84e8afb127fb4001bc4be
2c34ce1df23b838c5abf2a7f6437cca3d3067ed509ff25f11df6b11b582b51eb
07ec9bf950252d0254d4d778698c2e4173f36dbc3f57f51f34d1b85a07c2eab0
18619b678a5c207a971a0aa931604f48162e307c57ecdec450d5f095fe9f32c7
a365b37a503f29488c93f2656419e7d591002904360f6bdeb2ef2067fff23741
e4e9914396e8f86ac3f7756638894fccd794d3efa664cd873aedbfa6a9a7875b
a5645e7a3fa0866cde8842c4dab96567507c3d1a3c028b816bc63f6966367b70
02b1c2234680617802901a77eae606ad02e4ddb4282ccbc60061eac5b2d90bba
cc93ef06212aa60db1522de5a4ba79b389aa08ef7d5b29c3a8f1335b7a94aac1
f3cc103136423a57975750907ebc1d367e2985ac6338976d4d5a439f50323f4a
7862a192a3fca21f2445390973e52950159102b3a7ab1cd7117e9b1424e9805f
0abe90866c4fbc89ae5b4512dde9df1c441a2f5923ee3e7932cf34532a6bf773
3d5cbcd716866be8ca6eb87457294b1abe3a5473a326bb6dd39498aec8c8b044
4d5e25a4acedc3660f8ad38b1629fa719ea6fca82cf58bbed13c00b8c7c82996
ff8a7cfd199be01b74d6c4c0994cc26bbe4dde81714da2b933d075dcc2088920
Domains
www.microsoft.com
fs.microsoft.com
self.events.data.microsoft.com
ocsp.digicert.com
ecs.office.com
crl.microsoft.com
go.microsoft.com
officeclient.microsoft.com
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
activation-v2.sls.microsoft.com
www.chinadaily.com.cn
editor.svc.cloud.microsoft
messaging.engagement.office.com
oneocsp.microsoft.com
roaming.svc.cloud.microsoft
login.live.com
client.wns.windows.com
omex.cdn.office.net
messaging.lifecycle.office.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://www.chinadaily.com.cn/
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.3.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://officeclient.microsoft.com/config16/?lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16026&crev=3
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceasmayxgarewr3pgr9svwmg%3d
Last Seen at
Last Seen at

Recent blog posts

post image
Making Threat Intelligence Work for SOC Teams...
watchers 2351
comments 0
post image
5 Critical Pain Points of Modern US SOCs and...
watchers 4687
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 7155
comments 0

GREENBLOOD Ransomware: The Go-Powered Threat That Encrypts, Extorts, and Erases Its Tracks

Key Takeaways

  • GREENBLOOD is built for speed: Its Go-based ChaCha8 encryption engine can lock an entire Windows environment in minutes, collapsing the detection-to-impact window to near zero for signature-based defenses.

  • Double extortion doubles the damage: GREENBLOOD combines file encryption with data exfiltration and Tor-based leak site pressure, turning a ransomware incident into a simultaneous data breach with regulatory and reputational consequences.

  • Recovery is systematically blocked: Before encrypting a single file, GREENBLOOD deletes shadow copies, removes backup catalogs, disables WinRE, kills Defender, and turns off the firewall.

  • Self-deletion complicates forensics: The cleanup_greenblood.bat script removes the executable post-encryption, deliberately limiting the artifacts available for post-incident analysis and attribution.

  • Behavioral detection is the only viable pre-encryption defense. ANY.RUN's Interactive Sandbox captures the full GREENBLOOD attack chain, including shadow copy deletion, Defender disabling, and encryption, giving teams a clear verdict in under 60 seconds and enabling containment before downtime begins.

Observe GREENBLOOD detonated in the sandbox

GREENBLOOD malware analysis in Interactive Sandbox GREENBLOOD fresh sample analysis in Interactive Sandbox

  • ANY.RUN’s TI Lookup is your pivot engine: By searching for GREENBLOOD IOCs, command-line strings, mutexes, and behavioral patterns across millions of sandbox analyses, SOC and MSSP teams can uncover variants, enrich alerts, and harden detections faster than any manual process.

Start your research with the threat name and browse sandbox analyses to watch behavior and gather indicators:

threatName:"greenblood".

GreenBlood sandbox analyses found in TI Lookup GREENBLOOD sandbox analyses found in TI Lookup

What is GREENBLOOD Malware?

GREENBLOOD is an emerging ransomware family first identified in early 2026, operated by a threat actor group calling itself The Green Blood Group. Written in Go (Golang) and compiled as a Windows x64 executable, it is engineered for one overriding purpose: maximum disruption in minimum time.

Unlike older ransomware strains that limit themselves to file encryption, GREENBLOOD combines high-speed ChaCha8 encryption with aggressive defense evasion, systematic destruction of recovery options, and double-extortion pressure through a Tor-based data leak site. The result is a threat that transforms a technical security incident into a full-blown business crisis: downtime, regulatory exposure, reputational damage, and mounting ransom costs, within minutes of execution.

The ransomware follows a structured, multi-phase attack pattern. Before a single file is encrypted, it profiles the victim machine, collects a unique hardware identifier (system UUID), and then systematically dismantles the defenses and recovery mechanisms that would allow an organization to recover without paying.

Volume Shadow Copies are deleted, the Windows Backup catalog is purged, the Windows Recovery Environment is disabled, the Windows Firewall is turned off, and Microsoft Defender's real-time protection is killed via registry modification. Only after this preparation phase does the encryption engine engage.

Encryption itself is driven by a concurrent, routine-based engine that walks the filesystem in parallel — traversing all logical drives and shell folders such as Desktop, Documents, and Downloads — and queues files for rapid locking using ChaCha8, a modern stream cipher known for its speed. Encrypted files receive the .tgbg or .gblood extension, and a ransom note (READ_ME_TO_RECOVER_FILES.txt or !!!READ_ME_TO_RECOVER_FILES!!!.txt) is deposited in every affected directory. Each ransom note contains a unique victim Recovery ID, demands payment in Bitcoin within seven days (with escalating price thereafter and a 21-day key destruction deadline), and provides contact emails at Proton and OnionMail addresses.

Once encryption finishes, GREENBLOOD launches a cleanup batch script (cleanup_greenblood.bat) from the %LOCALAPPDATA%\Temp directory, which deletes the ransomware executable itself and scrubs artifacts — a deliberate attempt to reduce forensic visibility and complicate post-incident analysis. The entire execution chain, from initial profiling to self-deletion, can complete in a matter of minutes.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How GREENBLOOD Threatens Businesses and Organizations

GREENBLOOD doesn’t just compromise endpoints, it compromises decision-making time.

Key risks include:

  • Credential theft → lateral movement across systems;

  • Access resale → initial access brokers monetize your network;

  • Data exfiltration → intellectual property, financial data, customer records;

  • Ransomware staging → prepares infrastructure for high-impact attacks.

The real danger is delayed detection. By the time alerts fire, the attacker may already have mapped your environment.

Victimology: Which Industries Are Most at Risk?

The sectors most structurally vulnerable to GREENBLOOD’s type of attack include:

  • Healthcare: Patient data commands premium prices on dark markets, downtime is life-critical, and disclosure requirements are stringent. Healthcare led all industries in January 2026 ransomware incidents.

  • Financial services: High-value data, strict regulatory environments, and significant reputational stakes make payment more likely.

  • Manufacturing and industrial operations: Operational technology environments where downtime means immediate production and revenue loss.

  • Government and public sector: High-sensitivity data, often under-resourced security teams, and strong public pressure to restore services quickly.

  • Technology companies and IT service providers: Supply chain leverage — compromising one IT provider can cascade to dozens of downstream clients.

  • Education and research institutions: Large attack surfaces, valuable intellectual property, and historically limited security budgets.

Any organization running Windows environments with limited behavioral detection capability — particularly those relying on signature-based antivirus as a primary defense — is structurally at risk from GREENBLOOD.

How Can Businesses Proactively Protect Against GREENBLOOD malware

Proactive defense against a threat like GREENBLOOD requires moving beyond reactive, signature-based detection. ANY.RUN provides two complementary tools designed specifically for this purpose.

ANY.RUN Threat Intelligence Lookup

TI Lookup allows security teams to search across millions of sandbox analyses using rich, contextual queries — command-line strings, file hashes, mutex names, network indicators, and more. This pivoting capability allows analysts to find related variants, track infrastructure reuse, and expand detection coverage across the environment — going far beyond what a single IOC or signature can offer.

TI Lookup also highlights the regions and industry recently targeted by the malware.

syncObjectName:"GREENBLOOD_ENCRYPTOR_MUTEX_2A3B4C5D"

GreenBlood mutex queried in TI Lookup GREENBLOOD mutex queried in TI Lookup

ANY.RUN Threat Intelligence Feeds

TI Feeds deliver continuously updated, machine-readable threat intelligence — IP addresses, domains, URLs, and behavioral indicators associated with active threats including GREENBLOOD — directly into your existing security stack (SIEMs, firewalls, EDR, SOAR platforms). This means:

  • GREENBLOOD-associated infrastructure is automatically blocked at the perimeter before malware can establish communication or exfiltrate data.

  • Detection rules in your SIEM are continuously enriched with fresh IOCs, reducing the dwell time window.

  • Threat hunting teams have a structured, up-to-date dataset to search for compromised hosts or lateral movement indicators.

GreenBlood IOCs in TI Feeds GREENBLOOD IOCs in TI Feeds

Additional Protective Measures

  • Behavioral detection: Deploy EDR solutions capable of flagging shadow copy deletion, Defender disabling via registry, and rapid file rename events — all GREENBLOOD hallmarks — regardless of the malware's specific hash.

  • Immutable backups: Maintain offline or air-gapped backups that cannot be reached by a compromised Windows process. GREENBLOOD specifically targets recoverable backups, so only truly isolated backups provide meaningful protection.

  • Privilege restriction: Limit the number of accounts with local Administrator rights. GREENBLOOD's most destructive capabilities — disabling recovery, killing Defender, wiping shadow copies — only activate when running with admin privileges.

  • Network segmentation: Limit lateral movement capability by segmenting internal networks and enforcing least-privilege access between segments.

  • Employee security awareness: Phishing and malicious attachments remain primary delivery vectors for ransomware. Regular, realistic training and phishing simulations reduce the likelihood of initial access.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

How GREENBLOOD Gets in the System and Functions

GREENBLOOD's operators, consistent with modern professional ransomware groups, are not believed to rely on a single access vector. Based on observed behavior and infrastructure analysis, likely initial access methods include:

  • Phishing emails;

  • Exploitation of public-facing vulnerabilities;

  • Credential compromise;

  • Initial access brokers.

Once inside the network, GREENBLOOD's primary objective is to maximize the scope of encrypted systems before detection. The ransomware's concurrent, goroutine-based architecture means it does not process files sequentially — it spreads its encryption activity across multiple threads simultaneously, dramatically shortening the time required to impact the entire environment.

GREENBLOOD's execution flow breaks into several distinct phases:

Phase 1: Privilege and System Profiling

The binary checks for local Administrator group membership at runtime. If admin rights are confirmed, GREENBLOOD proceeds with its full recovery-inhibition and defense-suppression routine. It then collects the system UUID using Windows Management Instrumentation (wmic csproduct get uuid), generating a unique identifier per victim for key management and campaign tracking.

Phase 2: Recovery Destruction and Defense Suppression

Before encryption begins, GREENBLOOD executes a series of destructive commands:

  • vssadmin delete shadows /All /quiet — deletes all Volume Shadow Copies;

  • wmic shadowcopy delete — secondary shadow copy deletion;

  • wbadmin delete catalog -quiet — removes the Windows Backup catalog;

  • bcdedit /set {default} recoveryenabled No — disables Windows Recovery Environment;

  • bcdedit /set {default} bootstatuspolicy ignoreallfailures — suppresses boot failure warnings;

  • netsh advfirewall set allprofiles state off — disables Windows Firewall;

  • reg add ... DisableRealTimeMonitoring ... /d 1 — kills Defender real-time protection

Phase 3: Filesystem Traversal and Encryption

The EncryptionEngine — a developer-defined Go abstraction visible in the binary's preserved symbol names — uses a walkAndQueue method to traverse the filesystem. All logical drives and user shell folders are enumerated. A shouldEncryptFile function gates which files are processed. Qualifying files are encrypted using ChaCha8 and renamed with the .tgbg or .gblood extension. Ransom notes (READ_ME_TO_RECOVER_FILES.txt or !!!READ_ME_TO_RECOVER_FILES!!!.txt) are deposited in every directory containing encrypted files, with dynamically generated, per-victim Recovery IDs.

Phase 4: Extortion Infrastructure

Victims are directed to contact the operators via thegreenblood@proton[.]me or thegreenblood@onionmail[.]org, or to access the group's Tor-based leak site. Bitcoin payment is demanded within 7 days, with price escalation thereafter and a 21-day key destruction threat. The double-extortion model means non-payment results in stolen data being published on the leak site.

Phase 5: Self-Cleanup

Post-encryption, a batch script (cleanup_greenblood.bat) is executed from %LOCALAPPDATA%\Temp. This script deletes the ransomware executable and removes artifacts, deliberately hindering forensic analysis and incident reconstruction.

Sandbox Analysis of GREENBLOOD Malware Sample

See full execution chain of GREENBLOOD

ANY.RUN sandbox revealing GREENBLOOD behavior in real time ANY.RUN sandbox revealing GREENBLOOD behavior in real time

The ransomware creates a mutex at launch to ensure running a single copy in the system.

GREENBLOOD’s signature mutex GREENBLOOD’s signature mutex

When the encryption process begins, GREENBLOOD recursively scans directories and creates a queue of files to be encrypted. It filters out files from the predefined exclusion list (notably executables and critical system paths) to keep the system functional. Simultaneously, a ransom note is deployed.

The malware creates a ransom note The malware creates a ransom note

Finally, a batch script is executed to delete the ransomware executable.

The final stage of GREENBLOOD chain The final stage of GREENBLOOD chain

Conclusion

GREENBLOOD is not loud, flashy malware. It’s disciplined, adaptable, and patient. That combination makes it dangerous in modern environments where alert fatigue already clouds visibility.

Defending against it requires more than tools, it requires context. And context is exactly what strong threat intelligence delivers.

For businesses and security teams, the key lesson from GREENBLOOD is timing. The only effective defenses are those that operate before or during the early execution phase: behavioral detection, proactive threat intelligence, immutable backups, and a security architecture that assumes compromise and contains its blast radius.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Botnet screenshot
Botnet
botnet
A botnet is a group of internet-connected devices that are controlled by a single individual or group, often without the knowledge or consent of the device owners. These devices can be used to launch a variety of malicious attacks, such as distributed denial-of-service (DDoS) attacks, spam campaigns, and data theft. Botnet malware is the software that is used to infect devices and turn them into part of a botnet.
Read More
INC Ransomware screenshot
INC Ransomware is a ransomware-as-a-service (RaaS) spotted in mid-2023. It targets industries like retail, real estate, finance, healthcare, and education, primarily in the U.S. and UK. It encrypts and exfiltrates data demanding a ransom. It employs advanced evasion techniques, destroys backup, and abuses legitimate system tools at all the stages of the kill chain.
Read More
Quasar RAT screenshot
Quasar RAT
quasar trojan rat
Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.
Read More
LockBit screenshot
LockBit
lockbit
LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More
Keylogger screenshot
Keylogger
keylogger
A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.
Read More