Graybird is a Windows backdoor Trojan active since at least 2003 that hides on compromised systems, enables remote control by an attacker, and can download additional files from remote servers. It has been described both as a backdoor and as part of a broader wave of early Chinese-developed remote access Trojans, alongside families such as Glacier, Shady RAT, Net Thief, and YAI. Graybird has also been associated in some reporting with later GrayBird or Colony Sevya activity involving a downloader component and kernel drivers observed around 2017, indicating that the name has been used in multiple detection and clustering contexts.
Core behavior attributed to Graybird includes stealth on infected hosts, remote command capability, and retrieval of follow-on payloads. High-confidence reporting also indicates that some Graybird-associated activity installs Windows services backed by kernel drivers, uses encrypted check-in traffic, and collects host profiling data such as operating system version, locale, browser information, and network adapter details before communicating with command-and-control infrastructure. The use of drivers and hidden execution supports a defense-evasion role in addition to backdoor access.
Graybird targets Microsoft Windows systems and has been reported across a wide range of legacy Windows versions. Delivery has been associated with files dropped by other malware as well as user-initiated downloads from malicious websites. Historical reporting indicates the malware was prevalent in the mid-2000s and that development later declined, with some accounts stating the original project was abandoned as newer malware families became more effective.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware 2003 ... Gruel Graybird Blaster
A backdoor detected in the wild that arrives as a file dropped by other malware or downloaded unknowingly by users visiting malicious sites.
A downloader malware family associated with Onlineinstaller.exe that installs or uses kernel drivers (mrxsmb22.sys and amdfx.sys), checks in to a remote URL, downloads additional payloads, and uses AES-128-CBC-encrypted network traffic derived from packet data plus a hard-coded string.
2003 ... Gruel Graybird
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.