logo

GreyEnergy__2018__ESET_GreyEnergy.pdf

ID: 51576413-081a-4714-ba4e-ba572afa4485

STIX ID: report--51576413-081a-4714-ba4e-ba572afa4485

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2018-10-18

Last Modified Date: 2018-10-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET's report analyzes the GreyEnergy threat actor and malware family — a modular, sophisticated toolkit used in targeted attacks against critical infrastructure (notably energy and transportation) in Central and Eastern Europe — describing initial infection vectors (spearphishing, compromised web servers), GreyEnergy mini and full backdoor capabilities, persistence and in-memory execution techniques, proxy C2/triungulin infrastructure (often Tor relays), webshells, tools (Mimikatz, PsExec, port scanners), anti-analysis measures, a destructive Moonraker Petya worm variant, and extensive IOCs for detection and mitigation.