Greenbug is an Iran-linked cyberespionage group targeting organizations in the Middle East and South Asia. Its documented victims include telecommunications, aviation, government, investment, and education organizations. Telecommunications campaigns observed from at least April 2019 through April 2020 emphasized credential theft, persistent access, and access to internal database servers. Individual intrusions persisted for approximately six months. Greenbug uses custom remote-access malware, including ISMdoor and ISMAgent, alongside publicly available offensive frameworks and legitimate administrative utilities. Its initial-access techniques include email-delivered malicious documents, CHM and HTA payloads, and exploitation of Microsoft Office vulnerability CVE-2017-0199. Subsequent activity has involved Covenant, Cobalt Strike, Mimikatz, PowerShell, BITSAdmin, Plink, Bitvise, and webshells. The group steals credentials through password dumping, keylogging, and decryption of protected IIS database connection strings, then tests stolen credentials against internal database services. Persistence and internal access techniques include creating services and user accounts, granting administrative privileges, enabling PowerShell Remoting, and establishing tunnels for remote desktop access. Greenbug uses living-off-the-land techniques, hidden PowerShell execution, encoded payloads, and alternate data streams to reduce visibility. Its malware supports host and security-product reconnaissance, remote command execution, and data exfiltration. ISMdoor variants use HTTP or covert DNS-based command-and-control channels. Greenbug has also registered infrastructure impersonating Israeli technology and cybersecurity companies and a Saudi industrial company; this impersonation does not establish that those companies were compromised.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
117 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison in an otherwise unnamed actor profile; no campaign-specific activity is attributed to Greenbug.
Referenced as related background material in a detection rule for IIS connection string decryption; the content does not provide substantive details about Greenbug's activity in the body text.
Identified as an APT34 subgroup. No separate campaigns, targets, or malware are specified.
Espionage campaign targeting telecommunications companies in South Asia, using email-based initial infection, credential theft, living-off-the-land techniques, tunneling, webshells, and attempts to access database servers while maintaining long-term low-profile persistence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.