Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

GREENBLOOD

152
Global rank
148 infographic chevron month
Month rank
121 infographic chevron week
Week rank

GREENBLOOD is a Go-based ransomware that uses concurrent ChaCha8 encryption to lock entire Windows environments in under a minute while systematically destroying backups, disabling defenses, and threatening double extortion through a Tor-based data leak site.

Ransomware
Type
Unknown
Origin
1 February, 2026
First seen
14 September, 2026
Last seen

How to analyze GREENBLOOD with ANY.RUN

Type
Unknown
Origin
1 February, 2026
First seen
14 September, 2026
Last seen

IOCs

IP addresses
20.190.181.3
23.52.181.141
4.150.223.97
74.178.240.51
172.211.123.249
48.209.138.168
74.178.76.128
40.126.31.131
48.209.138.189
52.123.243.193
95.100.102.101
128.24.231.65
57.153.246.3
131.253.33.203
2.16.164.91
2.16.241.203
13.107.253.57
2.16.164.66
23.11.41.157
40.126.31.128
Hashes
648cafebd186d8c86a9ce22fabc64224888051c14808515493cc0a58047af7d9
b353b6e4c54b367f2c0beceddb42d163c8826b841cec4480337517dcc79431a1
bcd14f0f2cbfd87b0a15859d24b2caf2753c5c5b938bdbf4d5907b049f407469
d74ffeb92ebbdcdc4d8f63f7509964a858b4766becdcec2a3a830b61652b68cc
acad8f1eecf02fda8d4c9fe33ffbf524b9c1d8f255fe2a3180c9a65b5a827bff
55e1c653f3fb0a97726b2c363a5b3a72b9a900dae4b035694c96adcd6d20283e
80ef2da32175ae335ced1d8e5db743f6370dd4e3c1e99aff4cb694bdc7638d62
ddb358b31aa5f1410a4ddff0df1c848004f7549ad3aedd9fc39e0fb6010729be
13be0d08a0faec6526ccf33dc5d484ecb3ff13c066358e73609c8fc337638777
372f83e5d6dd8a4c31b1bcdafd4a3462c86c4a7475d3efcec60fe79b6d95ceae
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7
50fd06e788e316f8e3a3b553cffb09514fcf0068a2c3f28cc8fe3da5e228b8ec
1adaf2583878cde0fa5fcbfbde5613717cac8fdf17ec00bb2930eab0c2b35349
a614dc4ed7b3325e920e01bd2002de8ab95a750d634214645b5caa34024e704d
5af301dbde2e3f2ef19f83a63b733b5a244b14241ef868a4b0cbdbd33be075dd
eccd1e3cdf2eab080530575f8aa906b82e45e7508e38410c0dc79e4c1afa39a3
f1b6823c43bbdbe01192709ff9fc269b556371b0e8733eb1f6ea65c44d4f1389
087a86311bb5ab247caed53db29c1f626ef0a143cda9a76c0dd3880ff57f8d5d
380af3dc2a2cb0dd839e1b07fb763594c2498b86a399c971ffa72badd6ed373c
2d9c4ab240d79eacd2e244c4c300179c26dfef0daf723c841b08d4eb821c0447
Domains
login.live.com
www.microsoft.com
ocsp.digicert.com
go.microsoft.com
nexusrules.officeapps.live.com
settings-win.data.microsoft.com
slscr.update.microsoft.com
self.events.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
crl.microsoft.com
oneocsp.microsoft.com
client.wns.windows.com
activation-v2.sls.microsoft.com
ecs.office.com
google.com
www.bing.com
www.chinadaily.com.cn
officeclient.microsoft.com
watson.events.data.microsoft.com
r.bing.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceasmayxgarewr3pgr9svwmg%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbr0tbevyklx7a9ylold9hqmcwdxfgqu3pggslehmvkx8utfb6ncihnaqhycezmaaaale%2bvmfuqbvyaaaaaaaas%3d
https://self.events.data.microsoft.com/onecollector/1.0/
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://ecs.office.com/config/v2/office/officeclicktorun/16.0.16026.20140/production/cc?&clientid=%7b48ba7fdf-353c-4fe5-8d8f-9e31911a3891%7d&application=officeclicktorun&platform=win32&version=16.0.16026.20140&msoversion=16.0.16026.20140&processname=officeclicktorun.exe&audience=production&build=ship&architecture=x64&osversion=10.0&osbuild=19045&channel=cc&installtype=c2r&sessionid=%7b87bf6967-e8ad-4109-8d5a-f1b1113cb9eb%7d&labmachine=false
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.3.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
Last Seen at
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 2564
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 2932
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 4471
comments 0

GREENBLOOD Ransomware: The Go-Powered Threat That Encrypts, Extorts, and Erases Its Tracks

Key Takeaways

  • GREENBLOOD is built for speed: Its Go-based ChaCha8 encryption engine can lock an entire Windows environment in minutes, collapsing the detection-to-impact window to near zero for signature-based defenses.

  • Double extortion doubles the damage: GREENBLOOD combines file encryption with data exfiltration and Tor-based leak site pressure, turning a ransomware incident into a simultaneous data breach with regulatory and reputational consequences.

  • Recovery is systematically blocked: Before encrypting a single file, GREENBLOOD deletes shadow copies, removes backup catalogs, disables WinRE, kills Defender, and turns off the firewall.

  • Self-deletion complicates forensics: The cleanup_greenblood.bat script removes the executable post-encryption, deliberately limiting the artifacts available for post-incident analysis and attribution.

  • Behavioral detection is the only viable pre-encryption defense. ANY.RUN's Interactive Sandbox captures the full GREENBLOOD attack chain, including shadow copy deletion, Defender disabling, and encryption, giving teams a clear verdict in under 60 seconds and enabling containment before downtime begins.

Observe GREENBLOOD detonated in the sandbox

GREENBLOOD malware analysis in Interactive Sandbox GREENBLOOD fresh sample analysis in Interactive Sandbox

  • ANY.RUN’s TI Lookup is your pivot engine: By searching for GREENBLOOD IOCs, command-line strings, mutexes, and behavioral patterns across millions of sandbox analyses, SOC and MSSP teams can uncover variants, enrich alerts, and harden detections faster than any manual process.

Start your research with the threat name and browse sandbox analyses to watch behavior and gather indicators:

threatName:"greenblood".

GreenBlood sandbox analyses found in TI Lookup GREENBLOOD sandbox analyses found in TI Lookup

What is GREENBLOOD Malware?

GREENBLOOD is an emerging ransomware family first identified in early 2026, operated by a threat actor group calling itself The Green Blood Group. Written in Go (Golang) and compiled as a Windows x64 executable, it is engineered for one overriding purpose: maximum disruption in minimum time.

Unlike older ransomware strains that limit themselves to file encryption, GREENBLOOD combines high-speed ChaCha8 encryption with aggressive defense evasion, systematic destruction of recovery options, and double-extortion pressure through a Tor-based data leak site. The result is a threat that transforms a technical security incident into a full-blown business crisis: downtime, regulatory exposure, reputational damage, and mounting ransom costs, within minutes of execution.

The ransomware follows a structured, multi-phase attack pattern. Before a single file is encrypted, it profiles the victim machine, collects a unique hardware identifier (system UUID), and then systematically dismantles the defenses and recovery mechanisms that would allow an organization to recover without paying.

Volume Shadow Copies are deleted, the Windows Backup catalog is purged, the Windows Recovery Environment is disabled, the Windows Firewall is turned off, and Microsoft Defender's real-time protection is killed via registry modification. Only after this preparation phase does the encryption engine engage.

Encryption itself is driven by a concurrent, routine-based engine that walks the filesystem in parallel — traversing all logical drives and shell folders such as Desktop, Documents, and Downloads — and queues files for rapid locking using ChaCha8, a modern stream cipher known for its speed. Encrypted files receive the .tgbg or .gblood extension, and a ransom note (READ_ME_TO_RECOVER_FILES.txt or !!!READ_ME_TO_RECOVER_FILES!!!.txt) is deposited in every affected directory. Each ransom note contains a unique victim Recovery ID, demands payment in Bitcoin within seven days (with escalating price thereafter and a 21-day key destruction deadline), and provides contact emails at Proton and OnionMail addresses.

Once encryption finishes, GREENBLOOD launches a cleanup batch script (cleanup_greenblood.bat) from the %LOCALAPPDATA%\Temp directory, which deletes the ransomware executable itself and scrubs artifacts — a deliberate attempt to reduce forensic visibility and complicate post-incident analysis. The entire execution chain, from initial profiling to self-deletion, can complete in a matter of minutes.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How GREENBLOOD Threatens Businesses and Organizations

GREENBLOOD doesn’t just compromise endpoints, it compromises decision-making time.

Key risks include:

  • Credential theft → lateral movement across systems;

  • Access resale → initial access brokers monetize your network;

  • Data exfiltration → intellectual property, financial data, customer records;

  • Ransomware staging → prepares infrastructure for high-impact attacks.

The real danger is delayed detection. By the time alerts fire, the attacker may already have mapped your environment.

Victimology: Which Industries Are Most at Risk?

The sectors most structurally vulnerable to GREENBLOOD’s type of attack include:

  • Healthcare: Patient data commands premium prices on dark markets, downtime is life-critical, and disclosure requirements are stringent. Healthcare led all industries in January 2026 ransomware incidents.

  • Financial services: High-value data, strict regulatory environments, and significant reputational stakes make payment more likely.

  • Manufacturing and industrial operations: Operational technology environments where downtime means immediate production and revenue loss.

  • Government and public sector: High-sensitivity data, often under-resourced security teams, and strong public pressure to restore services quickly.

  • Technology companies and IT service providers: Supply chain leverage — compromising one IT provider can cascade to dozens of downstream clients.

  • Education and research institutions: Large attack surfaces, valuable intellectual property, and historically limited security budgets.

Any organization running Windows environments with limited behavioral detection capability — particularly those relying on signature-based antivirus as a primary defense — is structurally at risk from GREENBLOOD.

How Can Businesses Proactively Protect Against GREENBLOOD malware

Proactive defense against a threat like GREENBLOOD requires moving beyond reactive, signature-based detection. ANY.RUN provides two complementary tools designed specifically for this purpose.

ANY.RUN Threat Intelligence Lookup

TI Lookup allows security teams to search across millions of sandbox analyses using rich, contextual queries — command-line strings, file hashes, mutex names, network indicators, and more. This pivoting capability allows analysts to find related variants, track infrastructure reuse, and expand detection coverage across the environment — going far beyond what a single IOC or signature can offer.

TI Lookup also highlights the regions and industry recently targeted by the malware.

syncObjectName:"GREENBLOOD_ENCRYPTOR_MUTEX_2A3B4C5D"

GreenBlood mutex queried in TI Lookup GREENBLOOD mutex queried in TI Lookup

ANY.RUN Threat Intelligence Feeds

TI Feeds deliver continuously updated, machine-readable threat intelligence — IP addresses, domains, URLs, and behavioral indicators associated with active threats including GREENBLOOD — directly into your existing security stack (SIEMs, firewalls, EDR, SOAR platforms). This means:

  • GREENBLOOD-associated infrastructure is automatically blocked at the perimeter before malware can establish communication or exfiltrate data.

  • Detection rules in your SIEM are continuously enriched with fresh IOCs, reducing the dwell time window.

  • Threat hunting teams have a structured, up-to-date dataset to search for compromised hosts or lateral movement indicators.

GreenBlood IOCs in TI Feeds GREENBLOOD IOCs in TI Feeds

Additional Protective Measures

  • Behavioral detection: Deploy EDR solutions capable of flagging shadow copy deletion, Defender disabling via registry, and rapid file rename events — all GREENBLOOD hallmarks — regardless of the malware's specific hash.

  • Immutable backups: Maintain offline or air-gapped backups that cannot be reached by a compromised Windows process. GREENBLOOD specifically targets recoverable backups, so only truly isolated backups provide meaningful protection.

  • Privilege restriction: Limit the number of accounts with local Administrator rights. GREENBLOOD's most destructive capabilities — disabling recovery, killing Defender, wiping shadow copies — only activate when running with admin privileges.

  • Network segmentation: Limit lateral movement capability by segmenting internal networks and enforcing least-privilege access between segments.

  • Employee security awareness: Phishing and malicious attachments remain primary delivery vectors for ransomware. Regular, realistic training and phishing simulations reduce the likelihood of initial access.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

How GREENBLOOD Gets in the System and Functions

GREENBLOOD's operators, consistent with modern professional ransomware groups, are not believed to rely on a single access vector. Based on observed behavior and infrastructure analysis, likely initial access methods include:

  • Phishing emails;

  • Exploitation of public-facing vulnerabilities;

  • Credential compromise;

  • Initial access brokers.

Once inside the network, GREENBLOOD's primary objective is to maximize the scope of encrypted systems before detection. The ransomware's concurrent, goroutine-based architecture means it does not process files sequentially — it spreads its encryption activity across multiple threads simultaneously, dramatically shortening the time required to impact the entire environment.

GREENBLOOD's execution flow breaks into several distinct phases:

Phase 1: Privilege and System Profiling

The binary checks for local Administrator group membership at runtime. If admin rights are confirmed, GREENBLOOD proceeds with its full recovery-inhibition and defense-suppression routine. It then collects the system UUID using Windows Management Instrumentation (wmic csproduct get uuid), generating a unique identifier per victim for key management and campaign tracking.

Phase 2: Recovery Destruction and Defense Suppression

Before encryption begins, GREENBLOOD executes a series of destructive commands:

  • vssadmin delete shadows /All /quiet — deletes all Volume Shadow Copies;

  • wmic shadowcopy delete — secondary shadow copy deletion;

  • wbadmin delete catalog -quiet — removes the Windows Backup catalog;

  • bcdedit /set {default} recoveryenabled No — disables Windows Recovery Environment;

  • bcdedit /set {default} bootstatuspolicy ignoreallfailures — suppresses boot failure warnings;

  • netsh advfirewall set allprofiles state off — disables Windows Firewall;

  • reg add ... DisableRealTimeMonitoring ... /d 1 — kills Defender real-time protection

Phase 3: Filesystem Traversal and Encryption

The EncryptionEngine — a developer-defined Go abstraction visible in the binary's preserved symbol names — uses a walkAndQueue method to traverse the filesystem. All logical drives and user shell folders are enumerated. A shouldEncryptFile function gates which files are processed. Qualifying files are encrypted using ChaCha8 and renamed with the .tgbg or .gblood extension. Ransom notes (READ_ME_TO_RECOVER_FILES.txt or !!!READ_ME_TO_RECOVER_FILES!!!.txt) are deposited in every directory containing encrypted files, with dynamically generated, per-victim Recovery IDs.

Phase 4: Extortion Infrastructure

Victims are directed to contact the operators via thegreenblood@proton[.]me or thegreenblood@onionmail[.]org, or to access the group's Tor-based leak site. Bitcoin payment is demanded within 7 days, with price escalation thereafter and a 21-day key destruction threat. The double-extortion model means non-payment results in stolen data being published on the leak site.

Phase 5: Self-Cleanup

Post-encryption, a batch script (cleanup_greenblood.bat) is executed from %LOCALAPPDATA%\Temp. This script deletes the ransomware executable and removes artifacts, deliberately hindering forensic analysis and incident reconstruction.

Sandbox Analysis of GREENBLOOD Malware Sample

See full execution chain of GREENBLOOD

ANY.RUN sandbox revealing GREENBLOOD behavior in real time ANY.RUN sandbox revealing GREENBLOOD behavior in real time

The ransomware creates a mutex at launch to ensure running a single copy in the system.

GREENBLOOD’s signature mutex GREENBLOOD’s signature mutex

When the encryption process begins, GREENBLOOD recursively scans directories and creates a queue of files to be encrypted. It filters out files from the predefined exclusion list (notably executables and critical system paths) to keep the system functional. Simultaneously, a ransom note is deployed.

The malware creates a ransom note The malware creates a ransom note

Finally, a batch script is executed to delete the ransomware executable.

The final stage of GREENBLOOD chain The final stage of GREENBLOOD chain

Conclusion

GREENBLOOD is not loud, flashy malware. It’s disciplined, adaptable, and patient. That combination makes it dangerous in modern environments where alert fatigue already clouds visibility.

Defending against it requires more than tools, it requires context. And context is exactly what strong threat intelligence delivers.

For businesses and security teams, the key lesson from GREENBLOOD is timing. The only effective defenses are those that operate before or during the early execution phase: behavioral detection, proactive threat intelligence, immutable backups, and a security architecture that assumes compromise and contains its blast radius.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Salvador Stealer screenshot
Salvador Stealer
salvador
Salvador Stealer is a powerful, information-stealing Android malware designed to silently infiltrate systems, extract sensitive data, and exfiltrate it to cybercriminals. Often sold on underground forums, it is part of the growing ecosystem of “stealers-as-a-service” (SaaS) tools that target individuals and organizations alike.
Read More
Rootkit screenshot
Rootkit
rootkit bootkit
A rootkit is a type of malicious software designed to provide unauthorized administrative-level access to a computer or network while concealing its presence. Rootkits are tools used by cybercriminals to hide their activities, including keyloggers, spyware, and other malware, often enabling long-term system exploitation.
Read More
CastleLoader screenshot
CastleLoader
castleloader
CastleLoader is a modern malware loader designed to quietly establish initial access and deliver follow-up payloads such as stealers, RATs, and ransomware. It focuses on stealth, flexibility, and rapid payload rotation, making it an effective tool for financially motivated threat actors and a persistent problem for enterprise defenders.
Read More
DarkCloud screenshot
DarkCloud
darkcloud
DarkCloud is an infostealer that focuses on collecting and exfiltrating browser data from the infected device. The malware is also capable of keylogging and crypto address swapping. DarkCloud is typically delivered to victims’ computers via phishing emails.
Read More
PXA Stealer screenshot
PXA Stealer
pxastealer
PXA Stealer is an information-stealing malware that targets individuals and organizations in 60+ countries. It spreads via phishing, archives, and fake software updates. DLL sideloading, decoy documents, and obfuscation help it evade security tools. Exfiltrated data is exfiltrated and monetized through underground marketplaces.
Read More
DeerStealer screenshot
DeerStealer
deerstealer
DeerStealer is an information-stealing malware discovered in 2024 by ANY.RUN, primarily targeting sensitive data such as login credentials, browser history, and cryptocurrency wallet details. It is often distributed through phishing campaigns and fake Google ads that mimic legitimate platforms like Google Authenticator. Once installed, it exfiltrates the stolen data to a remote command and control (C2) server. DeerStealer’s ability to disguise itself as legitimate downloads makes it particularly dangerous for unsuspecting users.
Read More