ATT&CKSoftwareGreyEnergy

GreyEnergy

S0342

Malware.View on attack.mitre.org

About this malware

GreyEnergy is a backdoor written in C and compiled in Visual Studio. GreyEnergy shares similarities with the BlackEnergy malware and is thought to be the successor of it.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1003.001
LSASS Memory

GreyEnergy has a module for Mimikatz to collect Windows credentials from the victim’s machine.

T1007
System Service Discovery

GreyEnergy enumerates all Windows services.

T1027.002
Software Packing

GreyEnergy is packed for obfuscation.

T1027.013
Encrypted/Encoded File

GreyEnergy encrypts its configuration files with AES-256 and also encrypts its strings.

T1055.002
Portable Executable Injection

GreyEnergy has a module to inject a PE binary into a remote process.

T1056.001
Keylogging

GreyEnergy has a module to harvest pressed keystrokes.

T1059.003
Windows Command Shell

GreyEnergy uses cmd.exe to execute itself in-memory.

T1070.004
File Deletion

GreyEnergy can securely delete a file by hooking into the DeleteFileA and DeleteFileW functions in the Windows API.

T1071.001
Web Protocols

GreyEnergy uses HTTP and HTTPS for C2 communications.

T1090.003
Multi-hop Proxy

GreyEnergy has used Tor relays for Command and Control servers.

T1105
Ingress Tool Transfer

GreyEnergy can download additional modules and payloads.

T1112
Modify Registry

GreyEnergy modifies conditions in the Registry and adds keys.

T1218.011
Rundll32

GreyEnergy uses PsExec locally in order to execute rundll32.exe at the highest privileges (NTAUTHORITY\SYSTEM).

T1543.003
Windows Service

GreyEnergy chooses a service, drops a DLL file, and writes it to that serviceDLL Registry key.

T1553.002
Code Signing

GreyEnergy digitally signs the malware with a code-signing certificate.

View all 17 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET GreyEnergy Oct 2018 Open source
    Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.