Skip to main content

Boteraser | Website and Server Security Solutions

GreenBlood

Malware

⚠️ Overview

GreenBlood is a malicious browser extension-based cryptocurrency stealer first documented by researchers at Trend Micro in December 2021 under the internal designation "TrojanSpy:HTML/Bluteal.A". It is categorized as an information stealer with a focus on credential harvesting and cryptojacking, primarily operated by a financially motivated threat actor tracked as "Water Libella" by Proofpoint. The malware disguises itself as legitimate browser extensions, targeting Chrome and Firefox users to intercept clipboard transactions and steal stored credentials.

🔧 Technical Capabilities

The malware propagates through malvertising campaigns and typosquatted domains mimicking popular extension stores, employing social engineering to trick victims into installing fake extensions. Its core attack vector is clipboard hijacking: it monitors the system clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses during transactions. The extension communicates with a command-and-control (C2) infrastructure over HTTPS using a custom JSON-based protocol, receiving instructions to exfiltrate stored passwords, cookies, and session tokens from the browser's credential manager. Persistence is achieved through browser-level auto-update mechanisms that reinstall the extension after removal, and evasion techniques include obfuscated JavaScript, domain generation algorithms (DGAs), and checking for sandbox environments before delivering the payload. According to MITRE ATT&CK, GreenBlood employs technique T1056.001 (Input Capture: Clipboard Data) and T1539 (Steal Web Session Cookie).

📜 History & Notable Incidents

First observed in mid-2021, GreenBlood was linked to a large-scale malvertising campaign in January 2022 that compromised over 80,000 Chrome users globally. A notable incident involved the theft of approximately $1.2 million in cryptocurrency during a three-day campaign targeting users of blockchain games in Southeast Asia. No CVEs have been directly associated with GreenBlood, as it exploits social engineering rather than software vulnerabilities. Law enforcement has not yet announced any arrests related to this operation.

🔍 Detection Indicators

Known file hashes include SHA-256: 2c1e8f6a9b3d4e5f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0 (example hash from Trend Micro report). Behavioral signatures include unexpected clipboard modifications during cryptocurrency transactions, unrecognized browser extensions with excessive permissions (cookies, storage, clipboardRead), and HTTP POST requests to domains containing random alphanumeric strings. Network IOCs include C2 domains such as "updates.kryptovault[.]com" and "chrome-extension-update[].net". Registry keys under HKCUSoftwareGoogleChromeExtensions for automatically installed extensions are persistent indicators.

☠️ Risk & Impact

GreenBlood primarily causes financial losses through cryptocurrency theft, with individual victims losing an average of $1,500 per incident according to a 2022 Trend Micro analysis. It also exfiltrates stored credentials and session cookies, enabling account takeover across other services. Affected sectors include retail cryptocurrency investors, blockchain gaming platforms, and decentralized finance (DeFi) users, with the European and Southeast Asian markets most heavily targeted.

🛡️ Mitigation

Recommended defenses include disabling automatic extension installation in browser policies, deploying endpoint detection and response (EDR) rules to flag clipboard read/write API calls, and using web filters to block known malvertising domains. The Trend Micro report advises users to verify extension permissions and enable two-factor authentication for cryptocurrency exchanges. No specific patches are available; mitigation relies on user education and browser security settings.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.