Threats Feed|Greenbug|Last Updated 21/05/2026|AuthorCertfa Radar|Publish Date19/05/2020

Greenbug's Cyber Espionage Campaign Against South Asian Telecoms

  • Actor Motivations: Espionage
  • Attack Vectors: Backdoor,Downloader,Trojan,Phishing,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

The Greenbug espionage group is conducting an information-gathering campaign against telecommunications companies in South Asia. Using a mix of off-the-shelf tools and living-off-the-land techniques, the group primarily employs email as the initial infection vector. Notable files used for infection are proposal_pakistan110.chm:error.html and GRUNTStager.hta, often delivered through compromised websites via spearphishing. The group aims to gain access to database servers, leveraging tools like Covenant and custom malware like Trojan.Ismdoor. They have been observed using various PowerShell commands, Mimikatz, and Cobalt Strike, alongside multiple webshells. Living-off-the-land utilities such as Plink and Bitvise were used to establish tunnels back to attacker-controlled infrastructure.

Detected Targets

TypeDescriptionConfidence
SectorTelecommunication
Verified

Extracted IOCs

  • kopilkaorukov[.]com
  • vsiegru[.]com
  • apps.vvvnews[.]com
  • 0644b3ffc856eb54b53338ab8ecd22dd005ee5aacfe321f4e61b763a93f82aea
  • 069a29a0642ea5e2034250f5465cb2230edf1b49ad42d16ff4cddfee1f693314
  • 071e20a982ea6b8f9d482685010be7aaf036401ea45e2977aca867cedcdb0217
  • 16e1e886576d0c70af0f96e3ccedfd2e72b8b7640f817c08a82b95ff5d4b1218
  • 2a3f36c849d9fbfe510c00ac4aca1750452cd8f6d8b1bc234d22bc0c40ea1613
  • 3c6bc3294a0b4b6e95f747ec847660ce22c5c4eee2681d02cc63f2a88d2d0b86
  • 450ebd66ba67bb46bf18d122823ff07ef4a7b11afe63b6f269aec9236a1790cd
  • 471dadfe16cf2cf82566d404d2b7d1baf66b72c385ae272dcc743a285113e280
  • 4c7813a1f3eb5d5d8b8a1e53af074c96cfc6ddb14b21188fd84970f001bfc0ff
  • 53bbc9ebe40725bd74ebf29616f48a8aed0a544dd0e4f40801ac1b522f2cf32f
  • 6cb51c7011f27418c772124d4433350a534061f5732c1331f5483d62b42402f7
  • 75cee6136011516dfe7bd9e45b25c2cf5d9af149a81fff0b8b3ab157a8cbf321
  • 9809aeb6fd388db9ba60843d5a8489fea268ba30e3935cb142ed914d49c79ac5
  • 9bf8121e0f3461412dde107c4d1ceb2ed18ec0741f458956830e038fd1be6d44
  • 9de28b94aa3f1a849221cf74224554b41a77473c694cadf3f2526ab06480eb85
  • abb3ddc945d147a4ed435b71490764bc4a2860f4ad264052f407357911bd6746
  • b51eca570abad9341a08ae4d153d2c64827db876ee0491eb941d7e9a48d43554
  • b8797931ad99b983239980359ef0ae132615ebedbf6fcb0c0e9979404b4a02a8
  • e974237c32f5d28019c5328bd022469236da87eecee19487902133aea89432a0
  • ece23612029589623e0ae27da942440a9b0a9cd4f9681ec866613e64a247969d
  • ee32bde60d1175709fde6869daf9c63cd3227155e37f06d45a27a2f45818a3dc
  • f577fc8f22b6eec782dbcbe54f5a8f3b00e8e6d8dc7aa94b2fffcc2b7ce09c6a
  • faba07425c1fa65a9a68a17b99e83663a2a32fbb2a7c3df347b7a7411a7058bc
  • fc002268620fa67ffe260ea9f3a6bbad8637f9bef8ae85b8d6061cec0390b9e2
  • fd95ffb7c70f828ef021e7dbdaf852f54f385095e7f58607f093096b68f40a32
  • 185[.]205.210.46
  • 185[.]243.114.247
  • 185[.]243.115.69
  • 95[.]179.177.157
download

Tip: 32 related IOCs (4 IP, 3 domain, 0 URL, 0 email, 25 file hash) to this threat have been found.

Overlaps

OilRigOilRig's Steganography-Based C2 Channel Targets Middle Eastern Telecoms

Source: Palo Alto Networks - July 2020

Detection (three cases): ee32bde60d1175709fde6869daf9c63cd3227155e37f06d45a27a2f45818a3dc, apps.vvvnews[.]com, kopilkaorukov[.]com

OilRigUnraveling OilRig's Cyber Operations: Israel and Middle East in the Crosshairs

Source: Palo Alto Networks - September 2017

Detection (one case): 450ebd66ba67bb46bf18d122823ff07ef4a7b11afe63b6f269aec9236a1790cd

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Greenbug Cyber Attacks on South Asian Telecoms

Hackers successfully breached the computer networks of multiple telecommunications companies. Once inside, they remained hidden for months, quietly navigating the networks to steal passwords and gather sensitive information.

The attack was carried out by an espionage group known as "Greenbug." This group has a history of conducting cyber espionage and is known for using custom malware alongside everyday computer administration tools to avoid being caught.

The primary goal of this campaign was information gathering. Specifically, the attackers focused on stealing user credentials so they could log in to the organizations' central database servers and test their access.

The campaign targeted multiple telecommunications organizations across South Asia. In one documented case, the attackers maintained a presence on a victim's network for at least six months, from October 2019 to April 2020.

Yes, the attackers specifically went after companies in the telecommunications sector. Inside those companies, they explicitly targeted database servers and the sensitive records stored within them.

The hackers likely started by sending deceptive emails containing fake "proposal" documents that were actually malicious files. Once an employee opened the file, the hackers gained a foothold and used built-in Windows tools to secretly download more hacking software, steal passwords, and create hidden tunnels to control the network from the outside.

Telecommunications companies manage vast databases. The hackers were specifically trying to reach the database servers, which are highly attractive targets because they centralize a massive amount of valuable organizational information.

Organizations should be highly suspicious of unexpected email attachments, especially those claiming to have an "error" opening. Companies need to monitor their networks for the unauthorized use of normal administrative tools, secure their administrative passwords, and closely watch all traffic attempting to reach their sensitive database servers.

This is a highly targeted espionage campaign. Rather than trying to infect as many people as possible, the Greenbug group focused their efforts and custom techniques specifically on a select group of telecommunications providers in South Asia.

About Affiliation
Greenbug
Greenbug is an Iranian state-linked cyber espionage cluster active since at least 2016, first documented by Symantec. The group specializes in targeting telecommunications, internet service providers, aviation, and energy companies across Saudi Arabia, Iraq, Bahrain, Qatar, Kuwait, and Turkey using spear phishing with fake business proposals to deliver its custom Ismdoor remote access trojan. Ismdoor uses DNS tunneling — and later DNS TXT record-based command and control — enabling covert credential theft and keylogging while blending into normal DNS traffic. Symantec assessed that Greenbug likely provided the credentials used by the Shamoon operators in the November 2016 Disttrack attacks, after detecting an Ismdoor infection on an administrator machine at a Shamoon-targeted organization days before the wiper deployment. Unit 42 identified a modified ISMDoor variant called ISMAgent deployed by OilRig operators in 2017, establishing shared tooling between Greenbug and OilRig and suggesting the groups are closely linked or overlapping within the same Iranian state espionage infrastructure.
View Greenbug's Insights