Green Blood Group
Green Blood Group is a ransomware extortion actor active since at least early 2026.
Profile source: Mallory opens in a new tabGreen Blood Group
Family profile
Green Blood Group is a ransomware extortion actor active since at least early 2026. The group is associated with the aliases Green Blood, green_blood_group, and TH3 GR33N BL00D GROUP, and is linked to the GreenBlood ransomware family.
The operation conducts data encryption and extortion, with reported claims of data theft in addition to file locking. GreenBlood ransomware has been described as using combined symmetric and asymmetric encryption and appending a distinctive extension to encrypted files before presenting a ransom note that directs victims to contact the operators and pay for recovery. Reported delivery vectors include opportunistic intrusion paths commonly used by ransomware actors, such as exposed remote access services, phishing and malicious attachments, deceptive downloads, exploit-based compromise, malvertising, and trojanized installers.
Observed victimology indicates financially motivated targeting rather than a clearly defined ideological or state-directed mission. The group has been reported in connection with an intrusion affecting Senegal’s Directorate of File Automation, the government entity responsible for national identity infrastructure including ID cards, passports, and biometric records. In that incident, the actor publicly claimed to have exfiltrated a large volume of sensitive government data and the affected organization disclosed operational disruption. Claimed stolen material reportedly included identity-related and biometric information.
Available reporting supports classification of Green Blood Group as a ransomware gang rather than a nation-state threat actor. Publicly available information remains limited, and there is not yet sufficient high-confidence evidence to attribute the group to a specific country, broader intrusion cluster, or established ransomware cartel. Its known activity is currently best characterized as a low-prevalence ransomware operation engaged in encryption-based extortion and alleged data theft.
Ransomware.live
Operational record
MITRE ATT&CK