Ransomware Tracker (Entry #308): The Green Blood Group
ID: 08ce97e5-97ba-56e2-9011-fb62c9afd840
STIX ID: report--08ce97e5-97ba-56e2-9011-fb62c9afd840
Feed Name: WatchGuard Secplicity Blog
Threat Score
**Green Blood Group** operated a short-lived ransomware campaign between January and February 2026, deploying an encryptor (v1 and v2) that research and the group’s own notes indicate uses AES-256-CTR; the actor posted at least one confirmed victim (Senegal’s Directorate of File Automation) to a data-leak site and claimed several other breaches before the site went dark in mid-February 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
