Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

GREENBLOOD

150
Global rank
197 infographic chevron month
Month rank
193 infographic chevron week
Week rank
0
IOCs

GREENBLOOD is a Go-based ransomware that uses concurrent ChaCha8 encryption to lock entire Windows environments in under a minute while systematically destroying backups, disabling defenses, and threatening double extortion through a Tor-based data leak site.

Ransomware
Type
Unknown
Origin
1 February, 2026
First seen
22 July, 2026
Last seen

How to analyze GREENBLOOD with ANY.RUN

Type
Unknown
Origin
1 February, 2026
First seen
22 July, 2026
Last seen

IOCs

IP addresses
40.126.31.129
88.221.169.205
2.16.241.12
48.209.6.48
57.153.246.3
88.221.169.152
135.233.95.135
172.211.123.250
20.165.94.63
48.192.1.64
163.171.157.57
20.190.159.75
23.11.40.157
184.86.251.7
204.79.197.203
23.52.181.141
20.190.160.66
23.52.181.212
104.126.37.176
48.192.1.65
Hashes
9d908ecfb6b256def8b49a7c504e6c889c4b0e41fe6ce3e01863dd7b61a20aa0
4fe7b59af6de3b665b67788cc2f99892ab827efae3a467342b3bb4e3bc8e5bfe
79adab38bd93e2f14609db60ad34a2165e5ae868556f862c4569ae3d8a81a35e
bbfa41253ad301a1cd9c7f6321bff365068178f26cd84e8afb127fb4001bc4be
2c34ce1df23b838c5abf2a7f6437cca3d3067ed509ff25f11df6b11b582b51eb
07ec9bf950252d0254d4d778698c2e4173f36dbc3f57f51f34d1b85a07c2eab0
a365b37a503f29488c93f2656419e7d591002904360f6bdeb2ef2067fff23741
e4e9914396e8f86ac3f7756638894fccd794d3efa664cd873aedbfa6a9a7875b
a5645e7a3fa0866cde8842c4dab96567507c3d1a3c028b816bc63f6966367b70
cc93ef06212aa60db1522de5a4ba79b389aa08ef7d5b29c3a8f1335b7a94aac1
f3cc103136423a57975750907ebc1d367e2985ac6338976d4d5a439f50323f4a
7862a192a3fca21f2445390973e52950159102b3a7ab1cd7117e9b1424e9805f
4d5e25a4acedc3660f8ad38b1629fa719ea6fca82cf58bbed13c00b8c7c82996
ff8a7cfd199be01b74d6c4c0994cc26bbe4dde81714da2b933d075dcc2088920
d72511e843bf5a2e44e8bd1da20c2626311d1d6679424f717807a1db731d62f5
0693f6bfa2117a9b14f9ceca13d3a5611de5dca226bf999f20a7f615fbd08dff
0441772f66559a1c71f4559dc4405438fc9b8383ce1229139257a7fe6d7b8de9
3453f578e4f10a1cafd84b6500620ae42aeb9b31d700b3b9c3ef5498062a25d4
838f48e7795289411a2511787e131da15058f7df2745cffd3c9a3f4210aea7f1
d9de646d51650572b66a6cf8a52ad1efd46b7a47830fa7972da0bc05baa2fad0
Domains
fe3cr.delivery.mp.microsoft.com
settings-win.data.microsoft.com
slscr.update.microsoft.com
self.events.data.microsoft.com
go.microsoft.com
www.chinadaily.com.cn
activation-v2.sls.microsoft.com
www.microsoft.com
google.com
crl.microsoft.com
ocsp.digicert.com
www.bing.com
officeclient.microsoft.com
client.wns.windows.com
ecs.office.com
login.live.com
watson.events.data.microsoft.com
oneocsp.microsoft.com
r.bing.com
th.bing.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://www.chinadaily.com.cn/
https://login.live.com/rst2.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 4136
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 10033
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 12522
comments 0

GREENBLOOD Ransomware: The Go-Powered Threat That Encrypts, Extorts, and Erases Its Tracks

Key Takeaways

  • GREENBLOOD is built for speed: Its Go-based ChaCha8 encryption engine can lock an entire Windows environment in minutes, collapsing the detection-to-impact window to near zero for signature-based defenses.

  • Double extortion doubles the damage: GREENBLOOD combines file encryption with data exfiltration and Tor-based leak site pressure, turning a ransomware incident into a simultaneous data breach with regulatory and reputational consequences.

  • Recovery is systematically blocked: Before encrypting a single file, GREENBLOOD deletes shadow copies, removes backup catalogs, disables WinRE, kills Defender, and turns off the firewall.

  • Self-deletion complicates forensics: The cleanup_greenblood.bat script removes the executable post-encryption, deliberately limiting the artifacts available for post-incident analysis and attribution.

  • Behavioral detection is the only viable pre-encryption defense. ANY.RUN's Interactive Sandbox captures the full GREENBLOOD attack chain, including shadow copy deletion, Defender disabling, and encryption, giving teams a clear verdict in under 60 seconds and enabling containment before downtime begins.

Observe GREENBLOOD detonated in the sandbox

GREENBLOOD malware analysis in Interactive Sandbox GREENBLOOD fresh sample analysis in Interactive Sandbox

  • ANY.RUN’s TI Lookup is your pivot engine: By searching for GREENBLOOD IOCs, command-line strings, mutexes, and behavioral patterns across millions of sandbox analyses, SOC and MSSP teams can uncover variants, enrich alerts, and harden detections faster than any manual process.

Start your research with the threat name and browse sandbox analyses to watch behavior and gather indicators:

threatName:"greenblood".

GreenBlood sandbox analyses found in TI Lookup GREENBLOOD sandbox analyses found in TI Lookup

What is GREENBLOOD Malware?

GREENBLOOD is an emerging ransomware family first identified in early 2026, operated by a threat actor group calling itself The Green Blood Group. Written in Go (Golang) and compiled as a Windows x64 executable, it is engineered for one overriding purpose: maximum disruption in minimum time.

Unlike older ransomware strains that limit themselves to file encryption, GREENBLOOD combines high-speed ChaCha8 encryption with aggressive defense evasion, systematic destruction of recovery options, and double-extortion pressure through a Tor-based data leak site. The result is a threat that transforms a technical security incident into a full-blown business crisis: downtime, regulatory exposure, reputational damage, and mounting ransom costs, within minutes of execution.

The ransomware follows a structured, multi-phase attack pattern. Before a single file is encrypted, it profiles the victim machine, collects a unique hardware identifier (system UUID), and then systematically dismantles the defenses and recovery mechanisms that would allow an organization to recover without paying.

Volume Shadow Copies are deleted, the Windows Backup catalog is purged, the Windows Recovery Environment is disabled, the Windows Firewall is turned off, and Microsoft Defender's real-time protection is killed via registry modification. Only after this preparation phase does the encryption engine engage.

Encryption itself is driven by a concurrent, routine-based engine that walks the filesystem in parallel — traversing all logical drives and shell folders such as Desktop, Documents, and Downloads — and queues files for rapid locking using ChaCha8, a modern stream cipher known for its speed. Encrypted files receive the .tgbg or .gblood extension, and a ransom note (READ_ME_TO_RECOVER_FILES.txt or !!!READ_ME_TO_RECOVER_FILES!!!.txt) is deposited in every affected directory. Each ransom note contains a unique victim Recovery ID, demands payment in Bitcoin within seven days (with escalating price thereafter and a 21-day key destruction deadline), and provides contact emails at Proton and OnionMail addresses.

Once encryption finishes, GREENBLOOD launches a cleanup batch script (cleanup_greenblood.bat) from the %LOCALAPPDATA%\Temp directory, which deletes the ransomware executable itself and scrubs artifacts — a deliberate attempt to reduce forensic visibility and complicate post-incident analysis. The entire execution chain, from initial profiling to self-deletion, can complete in a matter of minutes.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How GREENBLOOD Threatens Businesses and Organizations

GREENBLOOD doesn’t just compromise endpoints, it compromises decision-making time.

Key risks include:

  • Credential theft → lateral movement across systems;

  • Access resale → initial access brokers monetize your network;

  • Data exfiltration → intellectual property, financial data, customer records;

  • Ransomware staging → prepares infrastructure for high-impact attacks.

The real danger is delayed detection. By the time alerts fire, the attacker may already have mapped your environment.

Victimology: Which Industries Are Most at Risk?

The sectors most structurally vulnerable to GREENBLOOD’s type of attack include:

  • Healthcare: Patient data commands premium prices on dark markets, downtime is life-critical, and disclosure requirements are stringent. Healthcare led all industries in January 2026 ransomware incidents.

  • Financial services: High-value data, strict regulatory environments, and significant reputational stakes make payment more likely.

  • Manufacturing and industrial operations: Operational technology environments where downtime means immediate production and revenue loss.

  • Government and public sector: High-sensitivity data, often under-resourced security teams, and strong public pressure to restore services quickly.

  • Technology companies and IT service providers: Supply chain leverage — compromising one IT provider can cascade to dozens of downstream clients.

  • Education and research institutions: Large attack surfaces, valuable intellectual property, and historically limited security budgets.

Any organization running Windows environments with limited behavioral detection capability — particularly those relying on signature-based antivirus as a primary defense — is structurally at risk from GREENBLOOD.

How Can Businesses Proactively Protect Against GREENBLOOD malware

Proactive defense against a threat like GREENBLOOD requires moving beyond reactive, signature-based detection. ANY.RUN provides two complementary tools designed specifically for this purpose.

ANY.RUN Threat Intelligence Lookup

TI Lookup allows security teams to search across millions of sandbox analyses using rich, contextual queries — command-line strings, file hashes, mutex names, network indicators, and more. This pivoting capability allows analysts to find related variants, track infrastructure reuse, and expand detection coverage across the environment — going far beyond what a single IOC or signature can offer.

TI Lookup also highlights the regions and industry recently targeted by the malware.

syncObjectName:"GREENBLOOD_ENCRYPTOR_MUTEX_2A3B4C5D"

GreenBlood mutex queried in TI Lookup GREENBLOOD mutex queried in TI Lookup

ANY.RUN Threat Intelligence Feeds

TI Feeds deliver continuously updated, machine-readable threat intelligence — IP addresses, domains, URLs, and behavioral indicators associated with active threats including GREENBLOOD — directly into your existing security stack (SIEMs, firewalls, EDR, SOAR platforms). This means:

  • GREENBLOOD-associated infrastructure is automatically blocked at the perimeter before malware can establish communication or exfiltrate data.

  • Detection rules in your SIEM are continuously enriched with fresh IOCs, reducing the dwell time window.

  • Threat hunting teams have a structured, up-to-date dataset to search for compromised hosts or lateral movement indicators.

GreenBlood IOCs in TI Feeds GREENBLOOD IOCs in TI Feeds

Additional Protective Measures

  • Behavioral detection: Deploy EDR solutions capable of flagging shadow copy deletion, Defender disabling via registry, and rapid file rename events — all GREENBLOOD hallmarks — regardless of the malware's specific hash.

  • Immutable backups: Maintain offline or air-gapped backups that cannot be reached by a compromised Windows process. GREENBLOOD specifically targets recoverable backups, so only truly isolated backups provide meaningful protection.

  • Privilege restriction: Limit the number of accounts with local Administrator rights. GREENBLOOD's most destructive capabilities — disabling recovery, killing Defender, wiping shadow copies — only activate when running with admin privileges.

  • Network segmentation: Limit lateral movement capability by segmenting internal networks and enforcing least-privilege access between segments.

  • Employee security awareness: Phishing and malicious attachments remain primary delivery vectors for ransomware. Regular, realistic training and phishing simulations reduce the likelihood of initial access.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

How GREENBLOOD Gets in the System and Functions

GREENBLOOD's operators, consistent with modern professional ransomware groups, are not believed to rely on a single access vector. Based on observed behavior and infrastructure analysis, likely initial access methods include:

  • Phishing emails;

  • Exploitation of public-facing vulnerabilities;

  • Credential compromise;

  • Initial access brokers.

Once inside the network, GREENBLOOD's primary objective is to maximize the scope of encrypted systems before detection. The ransomware's concurrent, goroutine-based architecture means it does not process files sequentially — it spreads its encryption activity across multiple threads simultaneously, dramatically shortening the time required to impact the entire environment.

GREENBLOOD's execution flow breaks into several distinct phases:

Phase 1: Privilege and System Profiling

The binary checks for local Administrator group membership at runtime. If admin rights are confirmed, GREENBLOOD proceeds with its full recovery-inhibition and defense-suppression routine. It then collects the system UUID using Windows Management Instrumentation (wmic csproduct get uuid), generating a unique identifier per victim for key management and campaign tracking.

Phase 2: Recovery Destruction and Defense Suppression

Before encryption begins, GREENBLOOD executes a series of destructive commands:

  • vssadmin delete shadows /All /quiet — deletes all Volume Shadow Copies;

  • wmic shadowcopy delete — secondary shadow copy deletion;

  • wbadmin delete catalog -quiet — removes the Windows Backup catalog;

  • bcdedit /set {default} recoveryenabled No — disables Windows Recovery Environment;

  • bcdedit /set {default} bootstatuspolicy ignoreallfailures — suppresses boot failure warnings;

  • netsh advfirewall set allprofiles state off — disables Windows Firewall;

  • reg add ... DisableRealTimeMonitoring ... /d 1 — kills Defender real-time protection

Phase 3: Filesystem Traversal and Encryption

The EncryptionEngine — a developer-defined Go abstraction visible in the binary's preserved symbol names — uses a walkAndQueue method to traverse the filesystem. All logical drives and user shell folders are enumerated. A shouldEncryptFile function gates which files are processed. Qualifying files are encrypted using ChaCha8 and renamed with the .tgbg or .gblood extension. Ransom notes (READ_ME_TO_RECOVER_FILES.txt or !!!READ_ME_TO_RECOVER_FILES!!!.txt) are deposited in every directory containing encrypted files, with dynamically generated, per-victim Recovery IDs.

Phase 4: Extortion Infrastructure

Victims are directed to contact the operators via thegreenblood@proton[.]me or thegreenblood@onionmail[.]org, or to access the group's Tor-based leak site. Bitcoin payment is demanded within 7 days, with price escalation thereafter and a 21-day key destruction threat. The double-extortion model means non-payment results in stolen data being published on the leak site.

Phase 5: Self-Cleanup

Post-encryption, a batch script (cleanup_greenblood.bat) is executed from %LOCALAPPDATA%\Temp. This script deletes the ransomware executable and removes artifacts, deliberately hindering forensic analysis and incident reconstruction.

Sandbox Analysis of GREENBLOOD Malware Sample

See full execution chain of GREENBLOOD

ANY.RUN sandbox revealing GREENBLOOD behavior in real time ANY.RUN sandbox revealing GREENBLOOD behavior in real time

The ransomware creates a mutex at launch to ensure running a single copy in the system.

GREENBLOOD’s signature mutex GREENBLOOD’s signature mutex

When the encryption process begins, GREENBLOOD recursively scans directories and creates a queue of files to be encrypted. It filters out files from the predefined exclusion list (notably executables and critical system paths) to keep the system functional. Simultaneously, a ransom note is deployed.

The malware creates a ransom note The malware creates a ransom note

Finally, a batch script is executed to delete the ransomware executable.

The final stage of GREENBLOOD chain The final stage of GREENBLOOD chain

Conclusion

GREENBLOOD is not loud, flashy malware. It’s disciplined, adaptable, and patient. That combination makes it dangerous in modern environments where alert fatigue already clouds visibility.

Defending against it requires more than tools, it requires context. And context is exactly what strong threat intelligence delivers.

For businesses and security teams, the key lesson from GREENBLOOD is timing. The only effective defenses are those that operate before or during the early execution phase: behavioral detection, proactive threat intelligence, immutable backups, and a security architecture that assumes compromise and contains its blast radius.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

BlackMatter screenshot
BlackMatter
blackmatter
BlackMatter is a ransomware strain operating as a Ransomware-as-a-Service (RaaS), designed to encrypt files, remove recovery options, and extort victims across critical industries. Emerging in 2021, it quickly became a major concern due to its ability to evade defenses, spread across networks, and cause large-scale operational disruption, forcing security teams to act against a highly destructive and persistent threat.
Read More
Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More
DarkTortilla screenshot
DarkTortilla
darktortilla
DarkTortilla is a crypter used by attackers to spread harmful software. It can modify system files to stay hidden and active. DarkTortilla is a multi-stage crypter that relies on several components to operate. It is often distributed through phishing sites that look like real services.
Read More
BQTLock screenshot
BQTLock
bqtlock baqiyatlock
BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration. BQTLock encrypts files using a hybrid AES-256 and RSA-4096 encryption scheme, demands payment in Monero cryptocurrency, and performs data theft and system reconnaissance.
Read More
X-Files screenshot
X-Files
xfiles
X-FILES Stealer is a sophisticated malware designed to infiltrate systems and steal sensitive information, targeting login credentials for email, social media, and other personal accounts. It captures data and transmits it back to the attacker’s command-and-control server. X-FILES Stealer employs advanced evasion techniques to avoid detection, making it a persistent threat in the cyber landscape.
Read More
WhiteSnake screenshot
WhiteSnake
whitesnake
WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.
Read More