GreenSpot (PoisonVine, APT-Q-20) is an APT group targeting Chinese entities primarily through phishing campaigns.
Analyst brief
GreenSpot (also known as PoisonVine, APT-Q-20) is an APT group targeting Chinese government, academic, and military entities primarily through phishing campaigns. The group focuses on credential theft from services like 163.com using deceptive domains, manipulated TLS certificates, and counterfeit interfaces. Defenders should enhance monitoring for irregular domain registrations, TLS certificate anomalies, and phishing emails targeting this specific email domain to detect and prevent credential harvesting attempts.
GreenSpot
PoisonVineAPT-Q-20
unknown
GreenSpot is an APT group believed to operate from Taiwan, active since at least 2007, primarily targeting government, academic, and military entities in China through phishing campaigns. The group frequently targets 163.com, aiming to steal login credentials using deceptive domains, manipulated TLS certificates, and counterfeit interfaces. Their tactics highlight the sophistication of modern credential theft operations, necessitating detection efforts focused on irregular domain registrations and certificate anomalies.
What is the primary attack method used by the GreenSpot APT group?+
GreenSpot primarily uses phishing campaigns, employing deceptive domains, manipulated TLS certificates, and counterfeit interfaces to steal login credentials.
What should defenders monitor to detect GreenSpot's attacks targeting email services like 163.com?+
Defenders should enhance monitoring for irregular domain registrations, TLS certificate anomalies, and phishing emails targeting the specific email domain.