GreyEnergy
Reports per quarter
Techniques seen in the last two years
- T1003.001 1 report
- T1053.005 1 report
- T1055 1 report
- T1059.001 1 report
- T1059.003 1 report
- T1082 1 report
- T1083 1 report
- T1090.002 1 report
- T1105 1 report
- T1124 1 report
Show all 14 techniques Show fewer
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2012-5687
- CVE-2013-5947
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4114 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-7248
- CVE-2015-7254
Show all 35 CVEs Show fewer
- CVE-2017-0199 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-9805 KEV
- CVE-2018-8453 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2018-8872
- CVE-2019-11510 KEV ransomware
- CVE-2019-15126
- CVE-2019-19781 KEV ransomware
- CVE-2020-15782
- CVE-2020-15892
- CVE-2020-15893
- CVE-2020-15894
- CVE-2020-15895
- CVE-2020-15896
- CVE-2020-3702
- CVE-2021-1675 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-34481
- CVE-2021-34527 KEV ransomware
- CVE-2021-36958
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Olympic Destroyer (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Olympic Destroyer (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlackEnergy (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor EternalPetya (Malware Family)
-
GreyEnergys overlap with Zebrocy.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GreyEnergys overlap with Zebrocy.pdf
-
Sandworm- A tale of disruption told anew
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sandworm- A tale of disruption told anew
-
Threat Update – Ukraine & Russia conflict
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Update – Ukraine & Russia conflict
Show all 38 reports Show fewer
-
Russian APT Uses COVID-19 Lures to Deliver Zebrocy - Intezer
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian APT Uses COVID-19 Lures to Deliver Zebrocy - Intezer
-
A Zebra in Gopher's Clothing- Russian APT Uses COVID-19 Lures to Deliver Zebrocy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Zebra in Gopher's Clothing- Russian APT Uses COVID-19 Lures to Deliver Zebrocy
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q32020
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Turla_ComRAT
-
Rich Headers- leveraging this mysterious artifact of the PE format
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rich Headers- leveraging this mysterious artifact of the PE format
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Ghost
-
Zebrocy Multilanguage Malware Salad
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Zebrocy Multilanguage Malware Salad
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET-LightNeuron
-
GreyEnergy Malware Research Paper- Maldoc to Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GreyEnergy Malware Research Paper- Maldoc to Backdoor
-
Threat Intel Reads – January 2019
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Intel Reads – January 2019
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Toolkit collection developed to help malware analysts dissecting and detecting the packer used by GreyEnergy samples.
-
GreyEnergy’s overlap with Zebrocy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GreyEnergy’s overlap with Zebrocy
-
GreyEnergy: Updated arsenal of one of the most dangerous threat actors
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor GreyEnergy: Updated arsenal of one of the most dangerous threat actors
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_GreyEnergy
-
ESET unmasks ‘GREYENERGY’ cyber-espionage group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ESET unmasks ‘GREYENERGY’ cyber-espionage group
-
GreyEnergy- Updated arsenal of one of the most dangerous threat actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GreyEnergy- Updated arsenal of one of the most dangerous threat actors
Newest first. Details opens the report in Explore.