The Green Blood Group is an emerging Go-based ransomware operation aggressive in destroying backup and recovery options.
Analyst brief
The Green Blood Group is an emerging ransomware operation first identified in early 2026. It targets organizations across India, Senegal, Egypt, Colombia, and Belgium. Its Go-based Windows payload leverages ChaCha8 encryption and aggressively destroys backup and recovery options. Defenders should prioritize isolating backup systems and monitoring for Go-based malicious activity.
thegreenbloodgroup
crime
The Green Blood Group is an emerging ransomware operation first identified in early 2026 whose Go-based Windows payload uses ChaCha8 encryption and aggressively destroys backup and recovery options, targeting organizations in India, Senegal, Egypt, Colombia, and Belgium.