GreyEnergy is a modular malware family tracked by ESET as part of a BlackEnergy successor subgroup closely linked to Sandworm. It was used in targeted intrusions against critical infrastructure organizations in Central and Eastern Europe, particularly in the energy and transportation sectors, as well as other high-value organizations; reporting also notes historical targeting of Polish energy companies and industrial networks in Ukraine and other countries. ESET assessed the activity was focused on reconnaissance and espionage, possibly in preparation for future disruptive attacks.
Initial compromise was reported via spearphishing and compromised public-facing web servers. When an internally hosted web server was compromised, operators used it for lateral movement, planted backup backdoors, and built internal proxy command-and-control chains that redirected traffic to external infrastructure. GreyEnergy has used Tor relays for command-and-control servers, and its communications were reported as encrypted with RSA-2048 and AES-256.
The malware set included a lightweight first-stage backdoor, GreyEnergy Mini, and a separate main module. GreyEnergy Mini collected and exfiltrated host and environment data including computer name, username, OS version, user privileges, proxy settings, user lists, IP addresses, domains, and antimalware details. The main module could run only in memory or be deployed with persistence. ESET reported in-memory-only deployment on high-availability servers, and in some cases the malicious DLL used for infection was securely wiped from disk, leaving the payload only in the memory of the hosting Windows service.
Observed capabilities include enumeration of all Windows services; registry modification and addition of keys; persistence by choosing an existing service, dropping a DLL, and writing it to the service's ServiceDLL registry key; secure file deletion by hooking DeleteFileA and DeleteFileW; credential theft via a Mimikatz module; collection of system information, event logs, malware hashes, file system data, screenshots, keystrokes, saved passwords, and user credentials; and local use of PsExec to execute rundll32.exe with NTAUTHORITY\SYSTEM privileges. GreyEnergy is also described as packed for obfuscation and digitally signed with a code-signing certificate; ESET reported samples signed with what appeared to be a stolen Advantech certificate.
GreyEnergy is widely described as conceptually similar to BlackEnergy and as a continuation of BlackEnergy/Sandworm activity, with reported overlaps with TeleBots and shared infrastructure/tooling. ESET published indicators of compromise for GreyEnergy on GitHub.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm's track record also includes a string of attacks – BlackEnergy, GreyEnergy and the first iteration of Industroyer – that targeted energy providers.
ESET researchers have discovered and analyzed advanced malware, previously undocumented, that has been used in targeted attacks against critical infrastructure organizations in Central and Eastern Europe. The malware, named GreyEnergy by ESET researchers, exhibits many conceptual similarities with BlackEnergy...
30 distinct techniques documented for this family, organized by ATT&CK tactic.
When a Web server is hosted internally and connected to the rest of an organization's network, the attackers have typically used that to try and move laterally on the network and plant backup backdoors so they can reinfect a victim network if their malware is spotted and removed.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
“Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer… replaced the ImagePath registry value of a Windows service with a new backdoor binary… [multiple groups/malware] creating a service / installing as a service / modifying service configurations for persistence.”
“Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer… replaced the ImagePath registry value of a Windows service with a new backdoor binary… [multiple groups/malware] creating a service / installing as a service / modifying service configurations for persistence.”
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
APT29 has used SDelete to remove artifacts from victim networks. FIN5 uses SDelete to clean up the environment and attempt to prevent detection. SDelete deletes data in a way that makes it unrecoverable. | The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
GreyEnergy chooses a service, drops a DLL file, and writes it to that serviceDLL Registry key.
They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
GreyEnergy's main module can run either in memory only... The malware is installed so when the attackers are done, the malicious DLL file that is used to infect the system is securely wiped from disk, and the payload exists only in the memory of the Windows service that is hosting it.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The modules that ESET has observed so far include those for collecting system information, event logs, malware hashes, file system operations, screen shots, keystroke logs, saved passwords, and user credentials using the Mimikatz tool.
AsyncRAT can proxy C2 through a Tor client. Attor has used Tor for C2 communication. Cyclops Blink has used Tor nodes for C2 traffic. GreyEnergy has used Tor relays for Command and Control servers. Siloscape uses Tor to communicate with C2. WannaCry uses Tor for command and control traffic.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2. APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network.
“Sandworm Team pushed additional malicious tools onto an infected system…”; repeated throughout: “can download additional payloads/files/modules from C2” and “upload/download files to/from victim’s machine.”
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
Examples include: "encrypts some C2 with RSA", "RSA encryption for C2 communications", "hard-coded RSA public key", "RSA-2048", "RSA-4096", and "REvil has encrypted C2 communications with the ECIES algorithm". | Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by Sandworm in attacks targeting energy providers.
Named malware/toolset referenced as part of an actor arsenal; specific capabilities are not described in the provided content.
Industrial/ICS-focused malware activity cluster described as a continuation of BlackEnergy/Sandworm, with noted infrastructure overlap and use of an ICS 0-day.
GreyEnergy is a modular malware framework used by an APT group for espionage and reconnaissance, primarily targeting energy companies and critical infrastructure in Ukraine and Poland. It is a successor to BlackEnergy, focusing on stealth, modularity, and persistence, and is capable of backdoor access, file extraction, screenshot capture, keylogging, and credential theft. It has not been observed to contain destructive modules but is likely used for preparing future sabotage or supporting other APT operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.