Grayling is a China-based state threat actor known for DLL side-loading and using Cobalt Strike and Havoc.
Analyst brief
Grayling is a China-based nation-state threat actor first observed in early 2023. It primarily targets biomedical, government, and information technology sectors in Taiwan, Vietnam, the Solomon Islands, and the United States. The actor is characterized by distinctive DLL side-loading activity and leverages well-known tools such as Cobalt Strike and Havoc frameworks. Defenders should monitor for anomalous DLL side-loading patterns and known network indicators associated with Cobalt Strike and Havoc C2 communications.
Grayling
nation-state
Grayling activity was first observed in early 2023, when a number of victims were identified with distinctive malicious DLL side-loading activity. Grayling appears to target organisations in Asia, however one unknown organisation in the United States was also targeted. Industries targeted include Biomedical, Government and Information Technology. Grayling use a variety of tools during their attacks, including well known tools such as Cobalt Strike and Havoc and also some others.
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)