Grayling
- First seen
- 2023-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:47:20
Targeted industries: healthcare-and-pharmaceutical government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:us
Context
Grayling activity was first observed in early 2023, when a number of victims were identified with distinctive malicious DLL side-loading activity. Grayling appears to target organisations in Asia, however one unknown organisation in the United States was also targeted. Industries targeted include Biomedical, Government and Information Technology. Grayling use a variety of tools during their attacks, including well known tools such as Cobalt Strike and Havoc and also some others.
Reports & references
- Broadcom/Symantec — Grayling Taiwan Cyber Attacks (report)
Attributed from
- Grayling APT Taiwan Espionage Activity (campaign)