ESET has identified overlap between GreyEnergy and a Sofacy subset called Zebrocys activity. GreyEnergy malware has been detected attacking industrial and ICS targets, mainly in Ukraine. The same server was also used in a spearphishing email attachment sent by GreyEnergy (aka FELIXROOT), as mentioned in a FireEye report. Both sets of activity used the same servers at the same time and targeted the same organization. Both are believed to be a successor to BlackEnergy, which led to power outages in 2015.”]
Source: https://securelist.com/greyenergys-overlap-with-zebrocy/89506/

