GreyEnergy
ESET research reveals a successor to the infamous BlackEnergy APT group targeting critical infrastructure, quite possibly in preparation for damaging attacks
GreyEnergy is a threat actor succeeding BlackEnergy APT, targeting critical infrastructure for reconnaissance.
GreyEnergy is a threat actor identified as the successor to the BlackEnergy APT group, primarily targeting critical infrastructure sectors. It focuses on organizations in energy and transportation, likely conducting reconnaissance for future destructive attacks. Key TTPs involve custom malware and stealthy lateral movement within compromised networks, though specific tool details are currently limited. Defenders should heighten monitoring of ICS/SCADA environments for anomalous network traffic, suspicious remote connections, and unauthorized access attempts, while also reviewing logs for legacy BlackEnergy-related TTPs.
ESET research reveals a successor to the infamous BlackEnergy APT group targeting critical infrastructure, quite possibly in preparation for damaging attacks
GreyEnergy is considered the successor to the BlackEnergy APT group.
It primarily targets critical infrastructure sectors, specifically energy and transportation.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.