Greenbug is an Iran-nexus cyber-espionage group documented by Symantec that targets government, energy, aviation, and telecom organizations in Saudi Arabia and the Gulf using the Ismdoor backdoor, and is assessed to have provided credential-theft support preceding the destructive Shamoon 2 wiper attacks.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Greenbug was detailed by Symantec in January 2017 following the Shamoon 2 wiper wave against Saudi organizations in late 2016. Symantec observed Greenbug's Ismdoor backdoor on at least one Shamoon victim prior to destruction, leading to a medium-confidence assessment that Greenbug conducted credential-harvesting reconnaissance that enabled the Shamoon operators — a linkage noted here to keep the two clusters distinct: Greenbug is the espionage/access element, while the separately profiled Shamoon operators executed the Disttrack wiper. Greenbug has no MITRE Group ID, flagged here.
Operationally, Greenbug favored spearphishing to deploy Ismdoor (a PowerShell-oriented backdoor) alongside a suite of hacking tools for credential theft and lateral movement (including Mimikatz-style utilities and remote-execution tools). Its focus on harvesting valid credentials aligns with a pre-positioning role feeding both espionage and destructive follow-on operations.
MENA and the Gulf are the group's core theater. Symantec documented victims in Saudi Arabia across government, energy/aviation, and other sectors, with additional regional targets — consistent with Iranian strategic interest in Saudi and Gulf critical infrastructure. Later Symantec reporting (2019) observed Greenbug tooling against telecommunications organizations in South Asia, indicating continued but geographically shifted activity.
Distinct Greenbug-branded activity has not been prominently re-reported after 2019, so the group is assessed as dormant. It is included as a net-new Iranian espionage historical entry directly relevant to the region's destructive-operations history, flagged medium confidence and G-ID-less.