GreyEnergy__2018__ESET_GreyEnergy.pdf
ID: 51576413-081a-4714-ba4e-ba572afa4485
STIX ID: report--51576413-081a-4714-ba4e-ba572afa4485
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2018-10-18
Last Modified Date: 2018-10-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET's report analyzes the GreyEnergy threat actor and malware family — a modular, sophisticated toolkit used in targeted attacks against critical infrastructure (notably energy and transportation) in Central and Eastern Europe — describing initial infection vectors (spearphishing, compromised web servers), GreyEnergy mini and full backdoor capabilities, persistence and in-memory execution techniques, proxy C2/triungulin infrastructure (often Tor relays), webshells, tools (Mimikatz, PsExec, port scanners), anti-analysis measures, a destructive Moonraker Petya worm variant, and extensive IOCs for detection and mitigation.
