GreyEnergy is an advanced threat actor and malware cluster tracked by ESET as a successor subgroup of the BlackEnergy threat cluster after BlackEnergy activity faded following the December 2015 Ukraine power grid attack. ESET describes GreyEnergy as one of at least two BlackEnergy offshoots, alongside TeleBots, and reports code similarities, shared tooling, and operational overlap between GreyEnergy and TeleBots. GreyEnergy has been linked to targeted attacks against critical infrastructure organizations in Central and Eastern Europe, with primary targeting in Ukraine and additional activity in Poland. Reported victim sectors include energy, transportation, and other high-value organizations; ESET also states GreyEnergy focused on industrial networks and targeted ICS-related systems, including control workstations running SCADA software and servers, although ESET did not observe a GreyEnergy module specifically designed to impact ICS. Based on the cited reporting, GreyEnergy’s activity was primarily focused on reconnaissance and espionage, possibly in preparation for future disruptive or sabotage operations. ESET reported first spotting GreyEnergy in late 2015 and observed activity through mid-2018. Infection vectors included spearphishing with malicious attachments and compromise of public-facing web services connected to internal networks. GreyEnergy used a lightweight first-stage backdoor known as GreyEnergy Mini, also referred to as FELIXROOT, to collect host and environment information and support follow-on execution. Operators then conducted credential theft and lateral movement, using legitimate or dual-use tools including Mimikatz, PsExec, WinExe, Nmap, and a custom port scanner. GreyEnergy malware is described as modular and stealth-focused. The main backdoor could run only in memory or be deployed persistently via the Windows ServiceDLL registry mechanism. Reported capabilities include collection of system information, event logs, malware hashes, file system data, screenshots, keystrokes, saved passwords, and user credentials. ESET reported use of WMI queries, internal proxy command-and-control chains inside victim networks, HTTP(S)-based C2, encryption including AES-256 and RSA-2048, secure wiping of artifacts, USN journal cleaning, selective module deployment, and use of Tor relays for C2 infrastructure. Some samples were reportedly signed with a likely stolen Advantech code-signing certificate. ESET also reported that GreyEnergy deployed Moonraker Petya in December 2016, described as an early predecessor to NotPetya. GreyEnergy has been characterized by ESET as one of the most dangerous threat actors due to its continued evolution of BlackEnergy-derived tradecraft against critical infrastructure. Known related groups and aliases directly mentioned in the content are BlackEnergy, TeleBots, and the GreyEnergy Mini/FELIXROOT malware component.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
"GreyEnergy: Updated arsenal of one of the most dangerous threat actors," ESET Ireland , 18-Oct-2018.
GreyEnergy is an APT group, considered the successor to BlackEnergy, focused on espionage and reconnaissance against energy companies and critical infrastructure, primarily in Ukraine and Poland. The group uses a modular malware framework for stealthy operations, targeting ICS control workstations and servers, and has links to the TeleBots subgroup responsible for the NotPetya ransomware outbreak.
A subgroup evolved from BlackEnergy that targets critical infrastructure organizations in Central and Eastern Europe, with emphasis on reconnaissance and espionage against industrial networks and possible preparation for future disruptive attacks.
Successor activity cluster to BlackEnergy focused on targeted intrusions into critical infrastructure/industrial networks (energy, transportation) in Central/Eastern Europe, using GreyEnergy and GreyEnergy mini (FELIXROOT) backdoors, internal proxy C2 chains ("triungulin"), credential theft and lateral movement; occasionally deploys destructive disk-wiping components and used a NotPetya-like worm in 2016.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.