GreyEnergy is a modular Windows malware platform associated with the Sandworm threat cluster and widely regarded as a successor to BlackEnergy. It has been used in targeted intrusions against critical infrastructure organizations in Central and Eastern Europe, especially energy, transportation, industrial, and ICS-related entities, with a strong concentration on Ukraine. Operations involving GreyEnergy have been characterized primarily as reconnaissance and espionage, though the malware’s tradecraft and targeting profile indicate preparation for potentially disruptive follow-on activity.
GreyEnergy infections have been linked to spearphishing campaigns using malicious documents and to compromise of public-facing web servers. Campaigns commonly used a lightweight first-stage backdoor known as GreyEnergy Mini, followed by deployment of a more capable modular payload. The main malware can operate only in memory on selected systems or establish persistence for longer-term access. Persistence has been achieved through Windows service abuse by dropping a DLL and configuring a service’s ServiceDLL registry value, alongside broader Windows Registry modification. The malware has also used PsExec and rundll32.exe to execute components with elevated privileges.
The platform supports encrypted command-and-control over HTTP and HTTPS, with communications protected using AES-256 and RSA-2048, and some operations have used Tor relays to obscure command-and-control infrastructure. GreyEnergy is notable for stealth features including custom packing, encrypted configuration data and strings, dynamic API resolution, code signing with a certificate, anti-analysis junk code, and anti-forensic behavior such as secure deletion of files by hooking Windows file-deletion APIs. In some cases, the malicious DLL used during infection was wiped from disk, leaving the payload resident only in the memory of a hosting Windows service.
GreyEnergy is extensible through downloadable modules and payloads. Observed capabilities include keylogging, Windows credential theft through a Mimikatz module, remote process injection of portable executables, service enumeration, collection of system and environment information, screenshots, event log and file system collection, and use of legitimate administrative tools such as Mimikatz, PsExec, and Nmap during post-compromise activity. The malware family has remained relevant beyond its initial public reporting, with additional dropper variants observed in later years and conceptual overlap noted with later Sandworm tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
(4de5adb865b5198b4f2593ad436fceff, exploiting CVE-2017-11882) ... Similarly, we detected a spearphishing GreyEnergy document (a541295eca38eaa4fde122468d633083, exploiting CVE-2017-11882) | Like its predecessor, GreyEnergy malware has been detected attacking industrial and ICS targets, mainly in Ukraine.
The file (11227eca89cc053fb189fac3ebf27497) with the name “Seminar.rtf” exploited CVE-2017-0199 | Like its predecessor, GreyEnergy malware has been detected attacking industrial and ICS targets, mainly in Ukraine.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Like its predecessor, GreyEnergy malware has been detected attacking industrial and ICS targets, mainly in Ukraine.
In 2021, Dragos uncovered two new GREYENERGY dropper variants in the wild: one in March of 2021, and another in August 2021.
GreyEnergy and its accompanying toolset was typically prefaced with a phishing attack, containing malicious documents that would deploy “GreyEnergy mini”, a first-stage backdoor.
ESET researchers have discovered and analyzed advanced malware, previously undocumented, that has been used in targeted attacks against critical infrastructure organizations in Central and Eastern Europe. The malware, named GreyEnergy by ESET researchers, exhibits many conceptual similarities with BlackEnergy...
30 distinct techniques documented for this family, organized by ATT&CK tactic.
A second point of entry was via vulnerable public-facing web services that are connected to the organization’s internal network.
The attack on the Ukrainian power grid was prefaced with a phishing attack against a number of energy distribution companies. The phishing email contained a Word document that, when Macros were enabled, dropped the Black Energy malware to disk.
This same C2 server was also used in a spearphishing email attachment sent by GreyEnergy (aka FELIXROOT)... Another server we detected that was used both by Zebrocy and by GreyEnergy is 185.217.0[.]124. Similarly, we detected a spearphishing GreyEnergy document...
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The file ... with the name “Seminar.rtf” exploited CVE-2017-0199 ... “Seminar.rtf” downloaded a second stage document ... (4de5adb865b5198b4f2593ad436fceff, exploiting CVE-2017-11882) ... we detected a spearphishing GreyEnergy document ... exploiting CVE-2017-11882
The GreyEnergy dropper is protected using a custom packer with the following characteristics: Custom decryption algorithm LZW (variant) decompression algorithm Junk code & JMP instructions (anti-analysis)
The GreyEnergy dropper is protected using a custom packer with the following characteristics: Custom decryption algorithm LZW (variant) decompression algorithm Junk code & JMP instructions (anti-analysis) Memory wiping (anti-forensic) Dynamically-resolved WinAPIs Overlay data payload
The GreyEnergy dropper is protected using a custom packer with the following characteristics: ... Dynamically-resolved WinAPIs
GreyEnergy encrypts its configuration files with AES-256 and also encrypts its strings.
GreyEnergy has a module to inject a PE binary into a remote process.
The GreyEnergy dropper is protected using a custom packer with the following characteristics: ... Memory wiping (anti-forensic)
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
NotPetya ransomware caused worldwide damages due to its highly effective spreading mechanism combining the EternalBlue (MS17-010) vulnerability, credential dumping from infected systems and PsExec for lateral movement.
Both sets of activity used the same servers at the same time and targeted the same organization... different Zebrocy C2 servers, including 193.23.181[.]151 ... Another server we detected that was used both by Zebrocy and by GreyEnergy is 185.217.0[.]124 ... They retrieve additional data from the following URL...
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
GreyEnergy is referenced as an earlier Sandworm-linked malware family that Kapeka likely succeeds, with conceptual and configuration overlap noted between them.
Malware used by Sandworm in attacks targeting energy providers.
Espionage malware and toolset used against Ukraine, often delivered via phishing or vulnerable public-facing web services; includes a first-stage backdoor.
Backdoor malware capable of securely deleting files via Windows API hooks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.