Recommended Free Tools
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
GreyEnergy was not publicly shown to have caused a blackout. ESET disclosed the malware and associated activity on October 17, 2018, describing a modular espionage and reconnaissance operation targeting energy and other critical-infrastructure organizations, especially in Ukraine and Poland. Its importance lay in the access it sought around sensitive networks—including SCADA workstations—not in a demonstrated ability to operate the power grid.
What GreyEnergy was—and what “group” means
ESET used GreyEnergy for both a malware framework and the activity cluster associated with it. Calling it a hacking “group” is convenient shorthand, not proof of a publicly identified organization, membership list, or chain of command. Threat-research names typically group activity using technical evidence such as malware similarities, infrastructure, victim patterns, and execution methods.
ESET described GreyEnergy as likely related to, or a successor to, BlackEnergy. That is an analytical assessment based on several overlaps; it does not establish that every operation involved the same people. ESET also reported connections with the TeleBots activity cluster. These names help researchers track related campaigns, but they should not be mistaken for verified organizational identities or, by themselves, definitive proof of state attribution. ESET’s 2018 disclosure explains the basis and limitations of its assessment.
Why GreyEnergy raised concern in 2018
GreyEnergy appeared in a strategic environment already marked by cyberattacks on Ukraine’s energy sector. ESET said it had seen the activity in its telemetry for about three years before going public. Its white paper places the first sighting in late 2015, in an attack on a Polish energy company, and the latest GreyEnergy use covered by that report in mid-2018. Ukraine was the primary focus, followed by Poland; energy was the leading target sector, with transportation and other critical infrastructure also affected.
#1 Best Overall
The reported activity was chiefly about espionage and positioning: getting into networks, collecting information and credentials, and reaching systems used around industrial environments. Such access can be strategically valuable even without an immediate attempt to interrupt electricity. It may help an intruder understand network structure and identify sensitive systems or routes for future access. That is a risk implied by the observed targeting—not evidence that GreyEnergy carried out a later sabotage operation.
A timeline that separates three different stories
- December 2015: A cyberattack associated with BlackEnergy and KillDisk disrupted Ukrainian electricity service. ESET’s GreyEnergy white paper says approximately 230,000 people lost power.
- Late 2015: ESET’s first GreyEnergy sighting was an attack on a Polish energy company.
- December 2016: A separate Ukrainian power disruption was associated with Industroyer, malware capable of interacting with industrial-control protocols.
- October 17, 2018: ESET publicly disclosed GreyEnergy. The report’s newest observed use was in mid-2018, not 2026.
- April 2022: ESET and CERT-UA analyzed Industroyer2 in an attempted attack against a Ukrainian energy provider. ESET assessed Sandworm’s responsibility with high confidence.
- January 2026: ESET reported on newer destructive activity attributed to Sandworm, including DynoWiper in Poland, and referred to GreyEnergy as part of the group’s historical energy-sector activity.
The key correction to the dramatic headline is that the public evidence does not show GreyEnergy causing either earlier blackout. The 2015 incident is associated with BlackEnergy-era activity; the 2016 incident with Industroyer. GreyEnergy targeted energy organizations and SCADA-related systems, but ESET did not report a GreyEnergy module designed to directly control industrial processes. See ESET’s GreyEnergy white paper and its later Industroyer2 analysis.
How the campaign gained and expanded access
ESET documented two principal entry routes: compromised public-facing web services connected to internal networks, and spear-phishing emails with malicious attachments. Some malicious documents installed GreyEnergy mini, a lightweight first-stage backdoor that did not require administrator privileges.
After entering a network, operators mapped systems and sought credentials. ESET described use of tools including Nmap for network discovery and Mimikatz-related credential theft. Once the attackers obtained administrator privileges, they could deploy the fuller GreyEnergy backdoor. The full implant was found on high-uptime servers and workstations used to control or monitor industrial-control environments.
Rank #3
The malware was modular: operators could use different components according to the target and objective. Reported functions included remote process execution, collection of system and event-log information, file operations, screenshots, keylogging, password collection, SSH tunneling through Plink, and proxying through 3proxy. Some modules could be loaded into memory rather than stored on disk. ESET also reported internal servers being used as proxy command-and-control nodes and Tor relays in the external communications chain. These details describe observed techniques; no single tool or network connection is, by itself, proof of GreyEnergy activity.
ESET’s white paper also records a disk-wiping component in at least one case. That is evidence of limited destructive capability, but it does not demonstrate the ability to manipulate circuit breakers, protection relays, or other grid-control equipment. GreyEnergy’s public profile remained primarily one of espionage, reconnaissance, and access-building.
Rank #4
Why access to a SCADA workstation is not the same as controlling the grid
SCADA systems supervise or control industrial processes, but an organization’s network contains many layers. A compromised Windows workstation used by an engineering or operations team may expose information, credentials, or routes to other systems. It does not automatically mean an intruder has issued commands to a power-system device. Direct process manipulation requires the relevant access and capability, and ESET said it had not observed a GreyEnergy module specifically designed for ICS control.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
That distinction does not make the targeting harmless. Access around control environments can help an attacker learn how systems are arranged and where valuable access may exist. But the available public evidence supports describing GreyEnergy as probing and compromising organizations around critical infrastructure—not as a proven grid-control weapon.
Best Value
BlackEnergy, GreyEnergy and Industroyer: related context, different roles
| Activity or malware | What the public reporting establishes | Important qualification |
|---|---|---|
| BlackEnergy | Associated with the 2015 Ukrainian energy-sector attack, alongside KillDisk in ESET’s account. | Related to GreyEnergy in ESET’s technical assessment; not the same malware family. |
| GreyEnergy | A modular platform and activity cluster used mainly for espionage and reconnaissance against critical-infrastructure targets. | ESET did not report observing a dedicated ICS-control module; “successor” or “offshoot” describes an assessment, not proven personnel continuity. |
| Industroyer | Associated with the 2016 Kyiv disruption and capable of interacting with industrial-control protocols. | A separate malware family, not another name for GreyEnergy. |
| Industroyer2 | Analyzed in connection with an attempted attack against a Ukrainian energy provider in 2022. | ESET assessed Sandworm responsibility with high confidence; this does not establish that the operation was a GreyEnergy campaign. |
GreyEnergy and BlackEnergy shared reported traits including energy-sector targeting, modular design, a lightweight “mini” backdoor before fuller payloads, and Tor-related command-and-control infrastructure. ESET also noted victim overlap and chronology: GreyEnergy appeared as BlackEnergy activity receded. Together these are meaningful clustering indicators, not conclusive proof of a single team or formal succession. ESET described GreyEnergy and TeleBots as related but differentiated clusters: TeleBots was associated with destructive operations, while GreyEnergy was more focused on critical-infrastructure espionage and reconnaissance.
What operators of critical infrastructure can take from the case
GreyEnergy’s documented entry routes and targets support practical defensive priorities. They are general lessons, not indicators that any particular organization has been targeted:
- Harden and monitor public-facing services, especially those with routes into internal networks.
- Reduce the risk of spear-phishing attachments through filtering, user reporting, and controls on document execution.
- Segment IT and operational technology networks, and maintain visibility across the boundaries needed for detection and incident response.
- Watch for unusual credential collection, unexpected administrator activity, and reconnaissance on engineering workstations or high-uptime servers.
- Restrict administrative tools and investigate their use in context; legitimate utilities can also be used during intrusions.
- Maintain offline, tested recovery procedures and preserve forensic evidence in case access-building is followed by destructive activity.
GreyEnergy’s status today
GreyEnergy is best described as a historically documented malware family and activity cluster publicly disclosed in 2018. ESET’s report placed its latest observed use in mid-2018; that is the scope of the report, not proof that the activity ceased everywhere on that date. Later destructive operations should not automatically be relabeled GreyEnergy: ESET discussed Industroyer2 in 2022 and newer Sandworm-attributed activity in 2026 as distinct developments. The durable lesson is that quiet reconnaissance around critical systems can matter even when researchers have not found a payload that directly manipulates those systems.
Free tools Windows power users keep installed
One-click scans. No signup required.
Sources: ESET’s 2018 disclosure; ESET’s GreyEnergy white paper; Kaspersky ICS CERT’s technical overview; ESET’s Industroyer2 analysis; and ESET’s 2026 DynoWiper analysis.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

