Skip to main content
Mallory
3 malware families

GreenCharlie

Also known asgreencharlie

GreenCharlie is an Iran-based advanced persistent threat (APT) group involved in cyber-espionage and phishing operations. The provided content states the group has been active since at least 2020 and remained active through late 2024. It expanded its infrastructure beginning in May 2024 by registering numerous dynamic DNS (DDNS) domains themed to mimic legitimate cloud, document, and authentication services, supporting targeted phishing and rapid infrastructure turnover. The content specifically notes use of commercial registrars including Namecheap, DDNS providers including Dynu, DNSEXIT, Vitalwerks, Cloud DNS, FreeDNS, and Dia Systems, and TLDs including .info, .xyz, .icu, .network, .online, and .site. Example lure domains include activeeditor[.]info, webviewerpage[.]info, and documentcloudeditor.ddnsgeek[.]com; example DDNS domains include coldwarehexahash.dns-dynamic[.]net, uptime-timezone.dns-dynamic[.]net, and translatorupdater.dns-dynamic[.]net. The group’s malware framework is described as a multi-stage PowerShell toolset with variants named GORBLE, TAMECAT, and POWERSTAR. The malware uses layered obfuscation, Base64 decoding, bitwise transformation, AES decryption with hard-coded keying material, and in-memory execution to evade detection. The execution chain described in the content includes an initial downloader/decoder, a decryptor/executor referred to as KeyMaster or Borjol, and a C2 beacon. TAMECAT and POWERSTAR reportedly execute decrypted payloads via Invoke-Expression, while GORBLE uses ScriptBlock.Create. The final stage collects host details including operating system and computer name, formats them as JSON, encrypts and Base64-encodes the data, and exfiltrates it via HTTP POST to command-and-control infrastructure. The content maps GreenCharlie activity to MITRE ATT&CK techniques including T1583.001 (Acquire Infrastructure: Domains), T1566.002 (Phishing: Spearphishing Link), T1059.001 (Command and Scripting Interpreter: PowerShell), T1568 (Dynamic Resolution), and T1665 (Hide Infrastructure). Telemetry cited in the content links infrastructure usage to Iranian IP addresses and to communications involving privacy services including ProtonVPN and Proton Mail, which the source assesses as deliberate operational concealment. No aliases or sub-groups beyond the name GreenCharlie are provided in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

4 of 15 tactics8 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.001
Domains
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.002
Spearphishing Link
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
TA0011
Command and Control
2 techniques
T1568
Dynamic Resolution
T1665
Hide Infrastructure
IOCS

Observables

6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping5

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables6

Domains, IPs, and hashes tied to this actor, refreshed continuously.