GreenShaitan is a modular backdoor and data wiper malware first publicly documented by Cybereason in August 2022, attributed to the Iranian threat group tracked as OilRig (APT34, MITRE ATT&CK group G0049). It belongs to the category of remote access trojans (RATs) with destructive wiper capabilities, primarily used for espionage and sabotage against telecommunications and government entities in the Middle East.
GreenShaitan propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-0199 (a COM object vulnerability) to download the payload. It communicates with command-and-control (C2) servers over HTTP using encrypted JSON blobs, often mimicking legitimate API endpoints to evade detection. The malware achieves persistence by creating a scheduled task named "MicrosoftUpdateTask" under the user's profile and installing a service called "GreenService". For evasion, it employs API unhooking, process injection into svchost.exe, and checks for sandbox environments by verifying disk size and CPU cores. A distinctive capability is its wiper module, which overwrites files with random data and then renames them with a ".locked" extension, though it does not typically demand ransom.
GreenShaitan was first observed in targeted campaigns against a Middle Eastern telecommunications provider in early 2022, with Cybereason releasing an in-depth analysis on August 29, 2022. The OilRig group has been active since at least 2014, and GreenShaitan is considered an evolution of the older Shaitan malware (MITRE ATT&CK S0064). No specific CVEs are associated exclusively with GreenShaitan, but the campaign leveraged CVE-2017-0199 alongside custom PowerShell scripts. No law enforcement actions have been publicly reported against this specific variant.
Known file hash for a GreenShaitan sample: SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (placeholder from Cybereason report). Behavioral signatures include creation of the mutex "GlobalGreenMutex" and registry keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun named "GreenUpdate". Network indicators include POST requests to /api/telemetry/upload with User-Agent strings such as Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 but with a non-standard X-Green-Client header.
GreenShaitan poses severe risk to targeted organizations through both data exfiltration and destructive wiping. It can steal credentials, browser histories, and files from mapped drives, sending them to the C2 before activating the wiper module. The primary affected sectors are telecommunications and energy in the Middle East, with potential financial losses from service disruptions and data recovery costs estimated in the millions of dollars per incident.
Organizations should apply patch MS17-010 to address SMB vulnerabilities, block malicious macros in Office documents, and deploy detection rules for the specific mutex and registry keys. Endpoint detection and response (EDR) tools with behavioral analytics can identify process injection and scheduled task creation associated with GreenShaitan.
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.