A new threat has emerged, targeting critical infrastructure systems. The malware is called GreyEnergy and bears similarities to BlackEnergy. The GreyEnergy malware has not yet been found to have any destructive capabilities for the systems it infects. Its goal is to monitor systems and servers running SCADA software (Supervisory control and data acquisition). However, it has a modular structure, which means that its features can be further expanded.

ESET security researchers observed that the initial infection is done with a different malware called GreyEnergy mini, which does not require administrator privileges.
GreyEnergy mini's job is to "map" the network around the system it infects, and obtain the necessary credentials to take full control of the network. It achieves this using Nmap and Mimikats, two tools designed for system security auditing.
ESET researchers have been tracking GreyEnergy since 2015, when they discovered the malware had targeted a Polish electricity company. It is believed to be the successor to BlackEnergy, and they also found similarities with Telebot, also known as the NotPetya Attack.
“We have seen three separate instances of this malware targeting utility companies and other targets over the past three years,” said Anton Cherepanov, a senior security researcher at ESET who led the investigation.
The connection to the Telebot group was made in 2016 when GreyEnergy used a smaller, more destructive malware called Moonraker Petya. As the name suggests, it is similar to NotPetya, but with less advanced features, which suggests that there was likely some collaboration between the two.
