Grayling

First seen
2023-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:47:20

Targeted industries: healthcare-and-pharmaceutical government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:us

Context

Grayling activity was first observed in early 2023, when a number of victims were identified with distinctive malicious DLL side-loading activity. Grayling appears to target organisations in Asia, however one unknown organisation in the United States was also targeted. Industries targeted include Biomedical, Government and Information Technology. Grayling use a variety of tools during their attacks, including well known tools such as Cobalt Strike and Havoc and also some others.

Reports & references

  • Broadcom/Symantec — Grayling Taiwan Cyber Attacks (report)

Attributed from

  • Grayling APT Taiwan Espionage Activity (campaign)

External references