GreenSpot

Aliases: PoisonVine, APT-Q-20

First seen
2007-01-01 00:00:00
Origin
TW
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:20:27

Targeted industries: government-and-public-sector education-and-nonprofits defense-and-aerospace

Targeted regions: country_code:cn

Context

GreenSpot is an APT group believed to operate from Taiwan, active since at least 2007, primarily targeting government, academic, and military entities in China through phishing campaigns. The group frequently targets 163.com, aiming to steal login credentials using deceptive domains, manipulated TLS certificates, and counterfeit interfaces. Their tactics highlight the sophistication of modern credential theft operations, necessitating detection efforts focused on irregular domain registrations and certificate anomalies.

Reports & references

  • hunt.io — Greenspot Apt Targets 163Com Fake Downloads Spoofing (report)
  • antiy.net — Greenspotoperations Grow For Many Years (report)
  • virusbulletin.com — Vb2019 Paper Vine Climbing Over Great Firewall Longterm Attack Against China (report)

External references