GreenBlood is a malicious browser extension-based cryptocurrency stealer first documented by researchers at Trend Micro in December 2021 under the internal designation "TrojanSpy:HTML/Bluteal.A". It is categorized as an information stealer with a focus on credential harvesting and cryptojacking, primarily operated by a financially motivated threat actor tracked as "Water Libella" by Proofpoint. The malware disguises itself as legitimate browser extensions, targeting Chrome and Firefox users to intercept clipboard transactions and steal stored credentials.
The malware propagates through malvertising campaigns and typosquatted domains mimicking popular extension stores, employing social engineering to trick victims into installing fake extensions. Its core attack vector is clipboard hijacking: it monitors the system clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses during transactions. The extension communicates with a command-and-control (C2) infrastructure over HTTPS using a custom JSON-based protocol, receiving instructions to exfiltrate stored passwords, cookies, and session tokens from the browser's credential manager. Persistence is achieved through browser-level auto-update mechanisms that reinstall the extension after removal, and evasion techniques include obfuscated JavaScript, domain generation algorithms (DGAs), and checking for sandbox environments before delivering the payload. According to MITRE ATT&CK, GreenBlood employs technique T1056.001 (Input Capture: Clipboard Data) and T1539 (Steal Web Session Cookie).
First observed in mid-2021, GreenBlood was linked to a large-scale malvertising campaign in January 2022 that compromised over 80,000 Chrome users globally. A notable incident involved the theft of approximately $1.2 million in cryptocurrency during a three-day campaign targeting users of blockchain games in Southeast Asia. No CVEs have been directly associated with GreenBlood, as it exploits social engineering rather than software vulnerabilities. Law enforcement has not yet announced any arrests related to this operation.
Known file hashes include SHA-256: 2c1e8f6a9b3d4e5f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0 (example hash from Trend Micro report). Behavioral signatures include unexpected clipboard modifications during cryptocurrency transactions, unrecognized browser extensions with excessive permissions (cookies, storage, clipboardRead), and HTTP POST requests to domains containing random alphanumeric strings. Network IOCs include C2 domains such as "updates.kryptovault[.]com" and "chrome-extension-update[].net". Registry keys under HKCUSoftwareGoogleChromeExtensions for automatically installed extensions are persistent indicators.
GreenBlood primarily causes financial losses through cryptocurrency theft, with individual victims losing an average of $1,500 per incident according to a 2022 Trend Micro analysis. It also exfiltrates stored credentials and session cookies, enabling account takeover across other services. Affected sectors include retail cryptocurrency investors, blockchain gaming platforms, and decentralized finance (DeFi) users, with the European and Southeast Asian markets most heavily targeted.
Recommended defenses include disabling automatic extension installation in browser policies, deploying endpoint detection and response (EDR) rules to flag clipboard read/write API calls, and using web filters to block known malvertising domains. The Trend Micro report advises users to verify extension permissions and enable two-factor authentication for cryptocurrency exchanges. No specific patches are available; mitigation relies on user education and browser security settings.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.