Threats Feed|Greenbug|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date23/01/2017

The Possible Connection Between Greenbug and Shamoon Revealed

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Malware,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

The Greenbug cyberespionage group, active since June 2016, has been using Trojan.Ismdoor, a custom information-stealing remote access Trojan (RAT), and additional hacking tools to compromise organizations in the Middle East and a Saudi organization in Australia. The group targets sectors including aviation, energy, government, investment, and education, using spearphishing emails to deliver malicious payloads hidden in RAR archives. Once opened, the Trojan opens a backdoor and collects sensitive data, potentially facilitating further attacks. Notably, the group’s activity ceased a day before the destructive W32.Disttrack.B (Shamoon) attack in November 2016, suggesting a possible connection.

Detected Targets

TypeDescriptionConfidence
SectorFinancial
Verified
SectorGovernment Agencies and Services
Verified
SectorAerospace
Verified
SectorEnergy
The sectors targeted by the attack were the aviation, energy, government, investment, and education sectors.
Verified
SectorUniversity
Verified
RegionAustralia
Verified
RegionBahrain
Verified
RegionIran
Verified
RegionIraq
Verified
RegionKuwait
Verified
RegionQatar
Verified
RegionSaudi Arabia
The countries targeted by the attack were predominantly in the Middle East, specifically Saudi Arabia, Iran, Bahrain, Iraq, Qatar, Kuwait, and Turkey. Additionally, a Saudi organization in Australia was also targeted.
Verified
RegionTurkey
Verified

FAQs

Frequently Asked Questions About the Greenbug Espionage Campaign and Its Links to Shamoon

A cyber espionage group called Greenbug, active since at least June 2016, ran a sustained campaign against organizations in the Middle East using a custom remote access Trojan called ISMdoor. The group targeted sectors including aviation, energy, government, investment, and education. Symantec's investigation found that Greenbug's activity on at least one compromised network stopped a day before a destructive Shamoon wiper attack hit the same organization in November 2016, raising the possibility that Greenbug had passed stolen credentials to the Shamoon attackers.

The espionage campaign was carried out by Greenbug, an Iranian-linked cyber espionage group. Symantec assessed Greenbug as a distinct actor but noted infrastructure overlaps and a suspicious timing correlation with the Shamoon group, which is also believed to have Iranian connections. The exact relationship between the two groups — whether they are the same, affiliated, or simply sharing resources — has not been definitively confirmed.

Greenbug's primary goal was espionage — gaining persistent access to targeted organizations, collecting sensitive data, and harvesting credentials. The suspected link to Shamoon suggests a secondary purpose: feeding stolen credentials to a separate group to enable destructive, follow-on attacks. This two-stage model — espionage first, destruction second — makes Greenbug particularly dangerous for organizations in critical sectors.

Greenbug's campaign was primarily focused on the Middle East, with confirmed targets in Saudi Arabia, Iran, Bahrain, Iraq, Qatar, Kuwait, and Turkey. A Saudi organization operating in Australia was also targeted, showing the group's willingness to follow targets beyond the region. The campaign ran from at least June 2016 through November 2016, spanning multiple countries and industries over several months.

Greenbug targeted organizations in the aviation, energy, government, investment, and education sectors, primarily in the Middle East. Energy and government entities appear to be the highest-priority targets, consistent with Iranian state interests in monitoring regional rivals and critical infrastructure operators. The targeting of a Saudi organization in Australia also shows the group tracks specific entities regardless of their physical location.

Greenbug sent targeted spear phishing emails containing RAR archives with malicious .chm (Compiled HTML Help) files. When a recipient opened the file, ISMdoor was silently installed, opening a backdoor and beginning data collection. The group then used credential harvesting and keylogging tools to steal account credentials from the compromised environment. In at least one case, Greenbug's access to a network appeared to be handed off — with stolen credentials likely used by the Shamoon operators to deploy a destructive wiper days later.

Energy companies, government agencies, and aviation firms in the Middle East hold strategic and economic intelligence of high value to Iranian state interests — including infrastructure vulnerabilities, procurement data, and personnel information. These organizations also tend to hold valid domain credentials and have broad internal network access, making them useful entry points for a follow-on destructive attack. Saudi Arabia in particular has been a recurring target given its geopolitical rivalry with Iran.

Organizations should block RAR and .chm file attachments at the email gateway, as these are Greenbug's primary delivery mechanism. Multi-factor authentication should be enforced on all remote access services and email portals to reduce the impact of credential theft. Endpoint detection capable of identifying RAT activity and keylogging should be deployed, especially in energy, aviation, and government environments. After any intrusion, organizations should monitor for unusual credential use and consider the possibility that stolen credentials may be leveraged by a second threat actor for a destructive follow-on attack. Maintaining tested offline backups is essential given the Shamoon connection.

About Affiliation
Greenbug
Greenbug is an Iranian state-linked cyber espionage cluster active since at least 2016, first documented by Symantec. The group specializes in targeting telecommunications, internet service providers, aviation, and energy companies across Saudi Arabia, Iraq, Bahrain, Qatar, Kuwait, and Turkey using spear phishing with fake business proposals to deliver its custom Ismdoor remote access trojan. Ismdoor uses DNS tunneling — and later DNS TXT record-based command and control — enabling covert credential theft and keylogging while blending into normal DNS traffic. Symantec assessed that Greenbug likely provided the credentials used by the Shamoon operators in the November 2016 Disttrack attacks, after detecting an Ismdoor infection on an administrator machine at a Shamoon-targeted organization days before the wiper deployment. Unit 42 identified a modified ISMDoor variant called ISMAgent deployed by OilRig operators in 2017, establishing shared tooling between Greenbug and OilRig and suggesting the groups are closely linked or overlapping within the same Iranian state espionage infrastructure.
View Greenbug's Insights