Skip to content
Ransomware group

Green Blood Group

Green Blood Group is a ransomware extortion actor active since at least early 2026.

Profile source: Mallory opens in a new tab

Green Blood Group

Family profile

Green Blood Group is a ransomware extortion actor active since at least early 2026. The group is associated with the aliases Green Blood, green_blood_group, and TH3 GR33N BL00D GROUP, and is linked to the GreenBlood ransomware family.

The operation conducts data encryption and extortion, with reported claims of data theft in addition to file locking. GreenBlood ransomware has been described as using combined symmetric and asymmetric encryption and appending a distinctive extension to encrypted files before presenting a ransom note that directs victims to contact the operators and pay for recovery. Reported delivery vectors include opportunistic intrusion paths commonly used by ransomware actors, such as exposed remote access services, phishing and malicious attachments, deceptive downloads, exploit-based compromise, malvertising, and trojanized installers.

Observed victimology indicates financially motivated targeting rather than a clearly defined ideological or state-directed mission. The group has been reported in connection with an intrusion affecting Senegal’s Directorate of File Automation, the government entity responsible for national identity infrastructure including ID cards, passports, and biometric records. In that incident, the actor publicly claimed to have exfiltrated a large volume of sensitive government data and the affected organization disclosed operational disruption. Claimed stolen material reportedly included identity-related and biometric information.

Available reporting supports classification of Green Blood Group as a ransomware gang rather than a nation-state threat actor. Publicly available information remains limited, and there is not yet sufficient high-confidence evidence to attribute the group to a specific country, broader intrusion cluster, or established ransomware cartel. Its known activity is currently best characterized as a low-prevalence ransomware operation engaged in encryption-based extortion and alleged data theft.

Ransomware.live

Operational record

View group record ↗

MITRE ATT&CK

Green Blood Group in ATT&CK

4 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.