GreyEnergy is an advanced threat cluster assessed as a successor to BlackEnergy, also known as Sandworm, and is associated with targeted intrusions against critical infrastructure organizations in Central and Eastern Europe. Activity attributed to GreyEnergy was observed from late 2015 through mid-2018, with a primary focus on Ukraine and additional targeting in Poland and Kazakhstan. The group concentrated on industrial and ICS-adjacent environments, especially energy organizations, as well as transportation and other high-value entities. Its operations were characterized primarily by reconnaissance and espionage, with some evidence of preparatory access that could support later disruptive or destructive activity. GreyEnergy is widely described as one of the post-BlackEnergy subgroups that emerged after the 2015 Ukraine power grid attacks, alongside TeleBots. Reporting has noted code overlap, shared tooling, and operational links between GreyEnergy and TeleBots, including GreyEnergy’s deployment of an early Petya variant known as Moonraker Petya. GreyEnergy has also been linked through shared infrastructure and near-simultaneous victim targeting to Zebrocy, a Sofacy-associated subset, suggesting some degree of relationship or cooperation, although the exact nature of that relationship remains unresolved. Initial access commonly involved spearphishing with malicious documents exploiting vulnerabilities such as CVE-2017-0199 and CVE-2017-11882, as well as compromise of public-facing web services connected to internal networks. GreyEnergy used a lightweight first-stage backdoor known as GreyEnergy Mini, also referred to as FELIXROOT, to profile victims and stage follow-on payloads. The main GreyEnergy malware was modular and supported both fileless, in-memory execution and persistent deployment. Persistence mechanisms included abuse of Windows service DLL loading, while stealth measures included secure wiping of dropped components, encrypted configuration and communications, selective module deployment, forged metadata, and anti-forensic cleanup. Observed post-compromise behavior included extensive host and network reconnaissance, credential theft, keylogging, screenshot capture, exfiltration of system and security information, lateral movement, and establishment of internal proxy command-and-control chains inside victim environments. Operators also used legitimate administrative and offensive tools including Mimikatz, PsExec, WinExe, and Nmap. GreyEnergy malware and infrastructure design showed strong operational security, including use of Tor-relay-backed command-and-control and encrypted communications. Some samples were signed with a likely stolen code-signing certificate from Advantech. Although GreyEnergy was not publicly documented using a dedicated ICS-impact module, it targeted ICS-related systems and at least one deployment included a disk-wiping component.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The file (11227eca89cc053fb189fac3ebf27497) with the name “Seminar.rtf” exploited CVE-2017-0199
(4de5adb865b5198b4f2593ad436fceff, exploiting CVE-2017-11882) ... Similarly, we detected a spearphishing GreyEnergy document (a541295eca38eaa4fde122468d633083, exploiting CVE-2017-11882)
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Advanced intrusion activity targeting industrial and ICS organizations, with overlap in infrastructure and victimology with Zebrocy/Sofacy. The content describes spear-phishing operations, shared C2 infrastructure, and attacks against industrial companies in Kazakhstan and mainly ICS targets in Ukraine.
"GreyEnergy: Updated arsenal of one of the most dangerous threat actors," ESET Ireland , 18-Oct-2018.
GreyEnergy is an APT group, considered the successor to BlackEnergy, focused on espionage and reconnaissance against energy companies and critical infrastructure, primarily in Ukraine and Poland. The group uses a modular malware framework for stealthy operations, targeting ICS control workstations and servers, and has links to the TeleBots subgroup responsible for the NotPetya ransomware outbreak.
A subgroup evolved from BlackEnergy that targets critical infrastructure organizations in Central and Eastern Europe, with emphasis on reconnaissance and espionage against industrial networks and possible preparation for future disruptive attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.