GreenCube, also tracked as UNC3707, is an espionage threat actor known for targeting webmail infrastructure. The actor has been observed exploiting vulnerabilities in platforms such as Roundcube and Zimbra, reflecting an operational focus on remotely reachable email systems that can provide access to sensitive communications. Activity associated with GreenCube is characterized in available reporting as cyberespionage rather than financially motivated intrusion or disruptive operations. High-confidence public reporting in this context links GreenCube to exploitation of some of the same webmail vulnerabilities used by other espionage groups, but does not provide sufficient corroborated detail to attribute specific campaigns, malware families, victim sectors, or national affiliation beyond that webmail-focused espionage tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an espionage group targeting webmail servers (e.g., Roundcube and Zimbra) for email theft.
Named espionage group referenced as also exploiting webmail XSS vulnerabilities similar to those used in Operation RoundPress.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.