UNK_GreenSec
UNK_GreenSec is a threat cluster linked to TransferLoader malware and associated ransomware deployment. Reporting cited in the content describes the cluster as involved in ongoing malware campaigns and, in one mention context, as Russia-attributed or Russia-linked, though some campaign-level attribution remains low confidence. Researchers and reporting noted highly similar infrastructure and tradecraft overlaps between UNK_GreenSec and the Russia-linked operation TA829 (also known as Nebulous Mantis, Storm-0978, UNC2596, and RomCom/Void Rabisu/Tropical Scorpius in related reporting), including use of REM proxy services relaying traffic to newly created freemail accounts, SSH tunnels established with PuTTY PLINK, and IPFS services for utility hosting. Proofpoint assessed that the overlap could indicate a shared third-party infrastructure provider or that the clusters may be the same operation. UNK_GreenSec activity has been tied to TransferLoader, which later launches Morpheus and Metasploit ransomware strains. Separate reporting linked infrastructure used in the ZipLine campaign to UNK_GreenSec; ZipLine targeted supply chain-critical manufacturing and other organizations, especially in the United States, using contact-form initiated social engineering, fake NDA-themed lures, malicious ZIP archives, LNK-triggered PowerShell loaders, COM TypeLib hijacking persistence, and the MixShell backdoor, which used DNS TXT tunneling with HTTP fallback for command and control. Mentioned context also states UNK_GreenSec used NDA-themed lures in August 2025 to deliver the MixShell backdoor. Known alias in the provided content: unk_greensec.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Associated malware families
4 malware families attributed to this actor across reporting.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously reported activity using fake NDA documents to deliver the MixShell backdoor; mentioned here as a TTP overlap comparison rather than as the actor behind the current campaign.
Activity cluster delivering TransferLoader; assessed to share tactics/infrastructure with TA829/RomCom activity.
Mentioned only as an overlapping activity cluster with RomCom (shared elements implied), but the content does not provide specific independent TTPs, targeting, or tooling beyond the stated overlap.
UNK_GreenSec is a threat actor cluster linked to the ZipLine campaign, targeting supply chain-critical industries with in-memory malware and advanced social engineering.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.