Uptime Hamster: 21d 12h 3mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza GreyEnergy

GreyEnergy

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: Maldoc, GreyEnergy Dropper, GreyEnergy Min, FELIXROOT, incluyendo el desarrollo, distribución de herramientas maliciosas, APT GREYENERGY
Ver en IntelTracker → APTTrail →
GreyEnergy is an advanced persistent threat (APT) group that emerged around December 2015, acting as a successor to the BlackEnergy APT group, with its activity coinciding with BlackEnergy's operational decline. The group is assessed with high confidence to be of Russian origin, with strong connections to Russia's GRU. Its primary motivation is espionage and reconnaissance, often conducted in preparation for potential future cyber-sabotage attacks against critical infrastructure. What distinguishes GreyEnergy is its highly modular malware framework designed for stealth, employing partially encrypted and fileless modules that reside only in memory, and securely wiping malware components from hard drives to impede analysis and detection. The group also utilizes Tor relays for command and control communications. GreyEnergy is distinct from but closely related to both the BlackEnergy and TeleBots groups.

Aliases del actor

MaldocGreyEnergy DropperGreyEnergy MinFELIXROOTincluyendo el desarrollodistribución de herramientas maliciosasAPT GREYENERGY

Actores similares

apt-greyenergyactor · 1greyenergy-miniactor · 1greyenergy-groupactor · 1apt-leafmineractor · 1apt-luminousmothactor · 1apt-minidukeactor · 1apt-c-01actor · 2apt-c-27actor · 2apt-45actor · 2apt-c-37actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteupduckduckgo.comGreyEnergy Mini (Malware / Tools)
DLS / leak siteupduckduckgo.comGreyEnergy Mini (Malware / Tools)
Repositoriounknowngithub.comAPT GREYENERGY indicators and references
Repositoriounknowngithub.comAPT GREYENERGY indicators and references
Webunknownraw.githubusercontent.comAPT GREYENERGY indicators and references
Malware asociado
win.felixroot, win.grey_energy
Tecnicas MITRE
T1059.001 - PowerShell, T1059.003 - Windows Command Shell, T1140, T1059, T1083 - File and Directory Discovery, T1584.004 - Server
CVEs relacionadas
CVE-2025-50165
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
15
Actualizado
Wed, 01 Ju

Sectores objetivo (OSINT)

Energy & Utilities Transportation&WarehousingOil & GasInternet PublishingComputer Systems Design and Related Services