GreenCharlie is an Iran-based advanced persistent threat group engaged in cyber-espionage and phishing operations since at least 2020. The actor has remained active through late 2024 and is associated with infrastructure expansion designed to support targeted phishing and rapid operational turnover. GreenCharlie is known for using social-engineering lures themed to resemble legitimate cloud, document, and authentication services. Its operations have relied on spearphishing links and extensive use of dynamically resolved infrastructure, including large numbers of domains registered through commercial registrars and dynamic DNS providers. This infrastructure strategy supports concealment, resilience, and frequent rotation. The group’s malware framework is a multi-stage PowerShell toolset that includes variants referred to as GORBLE, TAMECAT, and POWERSTAR. The framework uses layered obfuscation, staged decoding and decryption, AES-protected payloads, and in-memory execution to reduce detection opportunities. Reported execution chains include an initial downloader and decoder, a decryptor and executor component, and a command-and-control beacon that gathers basic host information and exfiltrates it in encrypted form over HTTP. GreenCharlie has also been associated with infrastructure concealment practices involving privacy services. At a behavioral level, GreenCharlie is associated with resource development, spearphishing for initial access, PowerShell-based execution, dynamic-resolution command-and-control infrastructure, defense evasion through obfuscation and in-memory execution, and encrypted host-data exfiltration. Its observed tradecraft and stated mission profile align primarily with espionage activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.