Green Leakers
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Green Leakers is a threat actor that uses the alias Green Leakers and is known to operate from Iran. The group first came to public attention when it claimed responsibility for a second leak of alleged Iranian cyber‑espionage data that appeared on Telegram channels and Dark Web sites. In that leak Green Leakers stated that the material originated from the operations of the MuddyWater APT group. To distribute the leak the actors maintained two Telegram channels and two separate Dark Web portals where they offered the data for sale. Rather than releasing malware source code freely, they posted screenshots showing the source code of a MuddyWater command‑and‑control server and images of the corresponding server backends. Those images also contained unredacted IP addresses belonging to some of MuddyWater’s identified victims. The group did not provide any tools or code for free download, distinguishing their approach from the earlier Lab Dookhtegam leak. By charging for access to the leaked material Green Leakers operated as a data‑selling entity rather than a pure whistleblower.
The leaked material focused on exposing the infrastructure and victim list of MuddyWater, indicating that the group’s activity targeted the operational details of an Iranian cyber‑espionage actor. Their tactics, techniques and procedures consist of gathering internal images of command‑and‑control source code and backend interfaces and disseminating those images via messaging and hidden‑web platforms. No malware families or custom tools were released in the leak; the emphasis was on visual proof of existing C&C infrastructure. The operation represents a notable campaign in which Green Leakers successfully highlighted specific MuddyWater servers and associated victim IP addresses through the sale of screenshots on their Telegram and Dark Web channels. The group’s public presence remains limited to those two Telegram channels and the two Dark Web portals they continue to maintain for distributing similar material. No further malware development, exploitation techniques, or alternative targeting sectors have been publicly attributed to Green Leakers in the available reporting.
Incidents
Attributed incidents are available to members.
0 incidents