Malware
Gryxa
- First Reported
- Aug 28, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (2)
- ReliaQuest observed this directly in Gryxa, a financially motivated toolkit that turned legitimate RMM software into persistent access. Gryxa distributed its persistence across at least seven scheduled tasks, a ReliaQuest Report Tracks Top Attacker Techniques in June–August 2026
- ReliaQuest has identified a new toolkit, dubbed “Gryxa,” used by a financially motivated threat actor across 324 listed hosts. We assess that substantial portions were almost certainly built with a commercial AI coding Gryxa Toolkit Uses AI-Assisted Development and Monitors Its Removal
CVE (1)
Malware (2)
Threat Actors (5)
MITRE ATT&CK (14)
Vendors (4)
Products (14)
Tools (2)
Industries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.