Greenbug
Greenbug is an Iranian threat actor associated with espionage and credential theft activity. Reporting cited in the content links Greenbug to operations against organizations in South Asia’s telecommunications sector, to infrastructure and domain registrations impersonating Israeli high-tech and cybersecurity companies, and to activity connected to Saudi organizations in the context of Shamoon-related attacks. Researchers assessed Greenbug as a possible collaborator supporting Shamoon by stealing user credentials ahead of destructive attacks. Greenbug is associated with the ISMdoor/Ismdoor malware family and a remote access Trojan referred to in the content as Ism.exe/ISMAgent. The malware evolved across multiple versions, with later versions adding keylogging, Powercat-based shell access, and Mimikatz execution. Reported capabilities include self-update, self-removal, configuration retrieval, command execution, collection of extensive host and network information, enumeration of security products via WMI, credential theft, and deployment or execution of supporting tools such as WinIt.exe, Mimikatz, and PowerShell UAC-bypass scripts including Invoke-BypassUAC and Invoke-PsUACme. Greenbug used both HTTP- and DNS-based command and control. HTTP activity included communication with update.winappupdater.com over paths such as /Home/CC and /Home/CR, with additional referenced URIs /Home/SCV, /Home/BM, and /Home/AV. Later tradecraft shifted to covert DNS tunneling. The content states ISMAgent/Ismdoor used DNS AAAA queries and, in some reporting, DNS TXT records to create a bidirectional C2 channel for command delivery and data exfiltration. The DNS-based channel used specially crafted query names, IPv6 responses, and session identifiers, and was described as rare, covert, and suited to long-term operations. Infrastructure linked to Greenbug included command-and-control domains such as thetareysecurityupdate[.]com and securepackupdater[.]com, as well as a broader cluster of lookalike domains impersonating Israeli companies and one Saudi company. Published linked domains included outbrainsecupdater[.]com, securelogicupdater[.]com, wixwixwix[.]com, biocatchsecurity[.]com, corticasecurity[.]com, covertixsecurity[.]com, arbescurity[.]com, ymaaz[.]com, winsecupdater[.]com, dnsupdater[.]com, winscripts[.]net, allsecpackupdater[.]com, lbolbo[.]com, oospoosp[.]com, osposposp[.]com, znazna[.]com, mbsmbs[.]com, benyaminsecupdater[.]com, and ntpupdateserver[.]com. The content also notes overlap or linkage in reporting between ISMAgent/ISMDoor and OilRig DNS-tunneling tradecraft, including a statement that ISMAgent used a DNS tunneling protocol very similar to ISMDoor. However, only the directly stated association in the content is that Greenbug is linked to ISMDoor/ISMAgent.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Observables
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as related background material in a detection rule for IIS connection string decryption; the content does not provide substantive details about Greenbug's activity in the body text.
Referenced only as a separate cluster previously linked to ISMDoor; mentioned to contextualize similarities between ISMAgent and ISMDoor DNS-tunneling behavior.
Registered lookalike domains impersonating Israeli high-tech and cybersecurity companies, and used ISMdoor samples and related command-and-control infrastructure in a likely targeting campaign.
Credential-theft and remote access activity supporting Shamoon operations, including use of the Ismdoor RAT with DNS-based C2 (DNS tunneling/DNSMessenger-style) to issue commands and exfiltrate data; uses credential dumping (likely Mimikatz) and keylogging to harvest credentials ahead of destructive attacks.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.