GrayAlpha Operation is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
GrayAlpha Operation is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed August 6, 2026; most recent activity August 6, 2026.
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
GrayAlpha Operation is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
The most recent intelligence report mentioning GrayAlpha Operation on ThreatCluster is dated August 6, 2026.
Across ThreatCluster reporting, GrayAlpha Operation most frequently co-occurs with Carbanak, Malware, Phishing, Ransomware, Financial, among 12 tracked related entities.
The most significant recent cluster is “GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments” (2 articles · Updated August 6, 2026). GrayAlpha Operation appears across 1 threat cluster in total, listed above with sources.
GrayAlpha Operation appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.