MOSCOW — Cybersecurity firm WithSecure disclosed in January 2026 the discovery of a cyberespionage group it named GreyVibe, which has been conducting AI-enhanced attacks against Ukraine-related entities since at least August 2025. The group targets organizations across military, government, civilian, and business sectors with a focus on Ukrainian or Ukraine-affiliated institutions.

GreyVibe employs multiple attack chains, including PhantomMail, which delivers malicious ZIP or RAR archives via Google Drive and 4sync links, using decoy PDFs or fake error messages to deploy malware. Another method, PhantomClick, uses fake CAPTCHA or ClickFix pages impersonating Zoom and LAPAS sites to trick victims into running self-infecting commands through counterfeit Cloudflare verification prompts. The group also operates PrincessClub, a campaign using fake Ukrainian adult and dating websites to distribute FallSpy Android spyware and PhantomRelay or LegionRelay Windows malware, while DroneLink leverages counterfeit Ukrainian military charity sites themed around FPV drones and UAVs.

A fifth campaign, Nebo, uses fake “СПО НЕБО” Russian military communications login pages likely intended to deceive Ukrainian military personnel. WithSecure determined that GreyVibe’s lures are generated using AI tools such as ChatGPT, Ideogram AI, and Google Gemini, enabling the creation of realistic and detailed content. The group also used AI to develop custom obfuscators named LOOKVALPS, LOOKVALJS, DAYLIGHT, and TEASOUP, and likely used large language models to assist in creating the PowerShell-based remote access trojan LegionRelay.

LegionRelay supports file theft, screenshot capture, browser credential theft, and data exfiltration from Telegram and WhatsApp, while PhantomRelay enables system fingerprinting and command execution. GreyVibe also deployed FallSpy Android spyware, which collects contact lists, call logs, location data, media files, and SIM information. Researchers noted that GreyVibe’s activity aligns with Russian state interests and is linked to Russian-speaking operators in the Moscow time zone, based on malware panel language, code comments, and server configurations.

WithSecure states that GreyVibe “lacked the level of sophistication and operational discipline typically associated with mature nation-state actors.” The group uploaded test samples to public platforms and used Internet slang like ‘letsrollboyos’ and ‘cuteuwu’ in development artifacts—behavior uncommon among established state-backed groups. Researchers believe GreyVibe may include “current or former cybercriminal actors.” Evidence includes the use in early and test samples of a unique ISO builder associated with a group of former TrickBot members (UAC-0098) that targeted Ukraine at the start of the Russian invasion.

“What sets GREYVIBE apart is not raw technical skill, but operational ambition powered by AI. The group uses generative AI to punch above its weight – accelerating development, filling capability gaps, and generating a largely fresh operational profile that complicates tracking and attribution. It’s a preview of how lower-sophistication actors will increasingly operate,” said Mohammad Kazem Hassan Nejad, senior threat intelligence researcher. WithSecure added that GreyVibe’s extensive use of AI reduces historical backlinks to prior activity and warned that the group’s tradecraft is expected to evolve, increasing the complexity of detection and attribution.