GreyEnergy is a Russia-linked espionage-focused threat cluster assessed as a successor subgroup of BlackEnergy, also known as Sandworm, which has been attributed to the Russian GRU. Active from at least late 2015 through mid-2018, GreyEnergy primarily targeted critical infrastructure organizations in Central and Eastern Europe, with a strong emphasis on Ukraine and additional activity in Poland and Kazakhstan. Its targeting centered on industrial and ICS-adjacent environments, especially energy organizations, as well as transportation and other high-value entities. GreyEnergy is distinguished from the more overtly destructive TeleBots offshoot of the BlackEnergy ecosystem, but the two have been linked through code similarities, shared tooling, and operational overlap. GreyEnergy has also been reported to share infrastructure and victim overlap with Zebrocy, a Sofacy subset, suggesting some relationship or cooperation. GreyEnergy’s operational profile emphasized reconnaissance, credential access, and long-term access in industrial networks, likely to support future disruptive or destructive operations. Initial access has been observed via spearphishing documents and compromise of public-facing web services connected to internal networks. GreyEnergy commonly used malicious documents exploiting vulnerabilities such as CVE-2017-0199 and CVE-2017-11882. After foothold establishment, the group conducted internal reconnaissance and lateral movement using both custom malware and legitimate administrative tools including Nmap, Mimikatz, PsExec, and WinExe. Operations included planting backup backdoors, abusing compromised internal servers as reinfection points, and building internal proxy command-and-control chains to relay traffic outward and reduce exposure of external infrastructure. The malware framework is modular and stealth-oriented. A lightweight first-stage backdoor, GreyEnergy Mini, also known as FELIXROOT, collected host, user, privilege, network, proxy, software, and security-product information and supported download-and-execute and command execution tasks. The main GreyEnergy backdoor could run purely in memory or with persistence, including abuse of Windows service DLL loading mechanisms. Observed capabilities included system and event-log collection, file-system enumeration, screenshot capture, keylogging, saved-password theft, credential theft, and exfiltration. The operators used encryption, secure wiping, anti-forensics, and selective module deployment to minimize detection. Some samples were signed with a likely stolen code-signing certificate associated with Advantech. GreyEnergy has not been chiefly characterized as a ransomware actor, but it has been linked to at least one disk-wiping component and to deployment of Moonraker Petya, an early NotPetya-related precursor. Despite these links, the cluster is primarily known for espionage and preparatory access against critical infrastructure rather than for overt extortion or broad destructive campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The file (11227eca89cc053fb189fac3ebf27497) with the name “Seminar.rtf” exploited CVE-2017-0199
(4de5adb865b5198b4f2593ad436fceff, exploiting CVE-2017-11882) ... Similarly, we detected a spearphishing GreyEnergy document (a541295eca38eaa4fde122468d633083, exploiting CVE-2017-11882)
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Successor activity associated with Black Energy focused on espionage against Ukrainian targets.
Advanced intrusion activity targeting industrial and ICS organizations, with overlap in infrastructure and victimology with Zebrocy/Sofacy. The content describes spear-phishing operations, shared C2 infrastructure, and attacks against industrial companies in Kazakhstan and mainly ICS targets in Ukraine.
"GreyEnergy: Updated arsenal of one of the most dangerous threat actors," ESET Ireland , 18-Oct-2018.
GreyEnergy is an APT group, considered the successor to BlackEnergy, focused on espionage and reconnaissance against energy companies and critical infrastructure, primarily in Ukraine and Poland. The group uses a modular malware framework for stealthy operations, targeting ICS control workstations and servers, and has links to the TeleBots subgroup responsible for the NotPetya ransomware outbreak.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.