GreyEnergy

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[GreyEnergy](https://attack.mitre.org/software/S0342) is a backdoor written in C and compiled in Visual Studio. [GreyEnergy](https://attack.mitre.org/software/S0342) shares similarities with the [BlackEnergy](https://attack.mitre.org/software/S0089) malware and is thought to be the successor of it.(Citation: ESET GreyEnergy Oct 2018)

Associated Techniques (17)
ID ATT&CK Tactics
T1003.001 LSASS Memory -
T1007 System Service Discovery -
T1027.002 Software Packing -
T1027.013 Encrypted/Encoded File -
T1055.002 Portable Executable Injection -
T1056.001 Keylogging -
T1059.003 Windows Command Shell -
T1070.004 File Deletion -
T1071.001 Web Protocols -
T1090.003 Multi-hop Proxy -
T1105 Ingress Tool Transfer -
T1112 Modify Registry -
T1218.011 Rundll32 -
T1543.003 Windows Service -
T1553.002 Code Signing -
Used by Actors (1)
Metadata
ID: 126
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00