Relevance: primary · Type: background
Confidence100%
GreyVibe is a threat group that has been using AI-generated lures and custom malware tools to target entities in the military, government, civilian, and business sectors.
Relevance: primary · Type: event
Confidence100%
The GreyVibe cyberespionage campaign has been active since at least August 2025.
Relevance: primary · Type: background
Confidence100%
GreyVibe's campaign appears to align with Russian state interests.
Relevance: primary · Type: background
Confidence100%
Researchers cannot confidently classify GreyVibe as a nation-state operation.
Relevance: primary · Type: event
Confidence100%
Cybersecurity company WithSecure discovered GreyVibe's activity in January 2026.
Relevance: primary · Type: background
Confidence100%
WithSecure determined that GreyVibe's focus is on Ukrainian or Ukraine-related organizations.
Relevance: supporting · Type: background
Confidence100%
The link to a Russian-speaking threat actor is supported by the language used in malware panels, comments in code artifacts, and command-and-control server time configured to UTC+3 (Moscow time).
Relevance: supporting · Type: action
Confidence100%
GreyVibe used an attack chain named PhantomMail involving spear-phishing emails that delivered malicious ZIP/RAR archives via Google Drive and 4sync links, using decoy PDFs or fake errors while deploying malware.
Relevance: supporting · Type: action
Confidence100%
PhantomMail lures impersonated Ukrainian government, emergency, telecom, and energy entities.
Relevance: supporting · Type: action
Confidence100%
GreyVibe used an attack chain named PhantomClick involving fake CAPTCHA/ClickFix pages disguised as Zoom and LAPAS sites to trick victims into running self-infecting commands through fake Cloudflare verification prompts.
Relevance: supporting · Type: action
Confidence100%
GreyVibe used an attack chain named PrincessClub involving fake Ukrainian adult/dating websites that delivered FallSpy Android spyware and PhantomRelay or LegionRelay Windows malware.
Relevance: supporting · Type: action
Confidence100%
In the PrincessClub campaign, operators used fake female Telegram personas and later added WebRTC-based live calls that could capture the victim's audio/video.
Relevance: supporting · Type: action
Confidence100%
GreyVibe used an attack chain named DroneLink involving fake Ukrainian military charity websites themed around FPV drones and UAVs that shared infrastructure and tooling with PrincessClub campaigns.
Relevance: supporting · Type: action
Confidence100%
GreyVibe used an attack chain named Nebo involving fake “СПО НЕБО” Russian military communications login pages likely designed to trick Ukrainian military personnel into believing they were accessing a Russian military terminal.
Relevance: supporting · Type: background
Confidence100%
WithSecure states that the diversity and quality of GreyVibe's lures result from using multiple AI tools, including ChatGPT, Ideogram AI, and Google Gemini, to generate detailed and realistic content.
Relevance: supporting · Type: action
Confidence100%
GreyVibe used AI in the creation of custom obfuscators named LOOKVALPS, LOOKVALJS, DAYLIGHT, and TEASOUP, which were likely developed with large language model (LLM) assistance.
Relevance: supporting · Type: background
Confidence100%
A PowerShell-based remote access trojan named LegionRelay was likely developed with assistance from AI tools.
Relevance: supporting · Type: background
Confidence100%
LegionRelay supports file theft, screenshot capturing, browser credential theft, Telegram and WhatsApp data exfiltration, and RDP access setup.
Relevance: supporting · Type: background
Confidence100%
GreyVibe also used PhantomRelay, a PowerShell remote access trojan that supports system fingerprinting, dynamic script loading, and PowerShell and Windows command execution.
Relevance: supporting · Type: action
Confidence100%
GreyVibe employed the FallSpy Android spyware in the PrincessClub and Nebo campaigns, which is designed purely for collecting intelligence.
Relevance: supporting · Type: background
Confidence100%
FallSpy collects contact lists, call logs, device and network information, location data, media files, and SIM information.
Relevance: supporting · Type: quote
Confidence100%
WithSecure notes that GreyVibe activity is consistent with a nation-state operation but the threat actor "lacked the level of sophistication and operational discipline typically associated with mature nation-state actors."
Relevance: supporting · Type: background
Confidence100%
PhantomRelay malware has been seen in cybercrime activity, although researchers could distinguish its usage from state-aligned operations.
Relevance: supporting · Type: quote
Confidence100%
Researchers believe GreyVibe may include "current or former cybercriminal actors."
Relevance: supporting · Type: background
Confidence100%
Evidence includes the use in early and test samples of a unique ISO builder associated with a group of former TrickBot members (UAC-0098) that targeted Ukraine at the start of the Russian invasion.
Relevance: supporting · Type: background
Confidence100%
GreyVibe uploaded development and test samples to a public scanning platform, which is not typical behavior for nation-state actors.
Relevance: supporting · Type: event
Confidence100%
A cryptocurrency miner was deployed on some victim machines.
Relevance: supporting · Type: quote
Confidence100%
Researchers are unsure "whether former or current cybercriminal members have been absorbed into a state-backed group, operate independently but with state-directed tasking, or have formed a hybrid team involving state-affiliated and cybercriminal members."
Relevance: supporting · Type: background
Confidence100%
Organizations can set up defenses against GreyVibe's malicious activity by using the indicators of compromise (IoCs) provided by WithSecure.
Relevance: primary · Type: background
Confidence100%
GreyVibe is described by WithSecure as a Russia-nexus group.
Relevance: primary · Type: background
Confidence100%
Researchers are confident in their attribution of GreyVibe to Russian-speaking operators in the Moscow time zone.
Relevance: supporting · Type: background
Confidence100%
Researchers detected the use of Internet slang-based naming conventions across early-stage development artifacts, such as ‘letsrollboyos’, ‘totallyunsus’, and ‘cuteuwu’.
Relevance: supporting · Type: background
Confidence100%
GreyVibe introduced design flaws into its LLM-generated LegionRelay Windows malware.
Relevance: supporting · Type: event
Confidence100%
The design flaws in LegionRelay enabled WithSecure researchers to monitor and track GreyVibe activity over an extended period since mid-2025.
Mohammad Kazem Hassan Nejad, senior threat intelligence researcher
Relevance: supporting · Type: quote
Confidence100%
"What sets GREYVIBE apart is not raw technical skill, but operational ambition powered by AI. The group uses generative AI to punch above its weight – accelerating development, filling capability gaps, and generating a largely fresh operational profile that complicates tracking and attribution. It’s a preview of how lower-sophistication actors will increasingly operate."
Relevance: supporting · Type: background
Confidence100%
GreyVibe used at least six distinct spear-phishing email campaigns, with no mention of deepfakes.
Relevance: supporting · Type: background
Confidence100%
GreyVibe's extensive use of AI reduces 'historical backlinks to prior activity.'
Relevance: supporting · Type: background
Confidence100%
WithSecure has found no evidence that GreyVibe has previously been tracked under a different name by other researchers.
Relevance: supporting · Type: background
Confidence100%
GreyVibe used a unique ISO builder potentially linked to the TrickBot ecosystem and UAC-0098, an activity cluster likely involving former TrickBot members previously observed targeting Ukraine.
Relevance: primary · Type: background
Confidence100%
GreyVibe is still active, and its members are still unknown.
Relevance: supporting · Type: quote
Confidence100%
"Given this extensive use, we expect the group’s tradecraft to continue evolving and diversifying, likely increasing the complexity of continuous detection, tracking, and attribution," says WithSecure.
forum Comments (0)
No comments yet. Be the first to comment.