UnknownUnknown

GrayCharlie

Threat actor tracked by Recorded Future. Further details pending analysis.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
3.9
Moderate signal strength
Mentions6
Sources1
High conf.4
Last seenMay 2026
First observed
Last active
Origin
Aliases
1
Techniques
0
Campaigns
0

Attribution signals

6 mentions · 1 source
#1activity byhigh
Infrastructure
recorded-future
May 2026

"sustained and widespread use of traffic distribution systems (TDS), including activity by TAG-124, GrayCharlie, and other threat actors"

#2is behindhigh
Unspecified
recorded-future
May 2026

"GrayCharlie is Insikt Group's designation for a threat activity group that first appeared in mid-2023 and is behind SmartApeSG, also referred to as ZPHP or HANEYMANEY."

#3linked tohigh
InfrastructureCode similarity
recorded-future
May 2026

"Insikt Group identified two main NetSupport RAT clusters linked to GrayCharlie based on factors such as TLS certificates, NetSupport serial numbers and license keys, and the timing of the activity"

#4likelyhigh
Victimology
recorded-future
May 2026

"Insikt Group identified a cluster of United States (US) law firm sites that were likely compromised around November 2025, possibly through a supply-chain compromise involving a shared IT provider."

#5assessesmoderate
Infrastructure
recorded-future
May 2026

"Insikt Group assesses that these clusters may correspond either to different individuals associated with GrayCharlie or to distinct GrayCharlie campaigns."

#6monitoringunspecified
Unspecified
recorded-future
May 2026

"Insikt Group has been monitoring GrayCharlie, a threat actor overlapping with SmartApeSG and active since mid-2023"

Hedge terms observed

activity byassessesis behindlikelylinked tomonitoring