GreyVibe AI‑Powered Cyberattacks Target Ukraine
Monitor for GREYVIBE activity targeting Ukrainian organizations and verify suspicious emails.
Enhance monitoring for suspicious activity targeting Ukrainian organizations and enforce MFA on critical accounts.
Summary
GreyVibe, a threat group believed to be linked to Russia, has intensified its cyber operations against Ukraine and other targets since August 2025. The group leverages advanced large‑language models such as ChatGPT, Google Gemini, Ideogram AI, and others to craft highly convincing phishing emails, fake CAPTCHA interfaces, and counterfeit adult‑dating sites. These lures deliver a suite of malware including the FallSpy Android spyware, and the Windows Remote Administration Tools (RATs) PhantomRelay and LegionRelay. In addition to phishing, GreyVibe runs campaigns that masquerade as charity or military login portals, such as DroneLink and Nebo, to harvest credentials and establish remote desktop access.
The attackers also employ AI‑assisted development of custom obfuscation tools—LOOKVALPS, LOOKVALJS, DAYLIGHT, and TEASOUP—to evade detection. Their PowerShell‑based RAT, LegionRelay, can exfiltrate credentials, create persistence, and set up RDP tunnels for lateral movement. GreyVibe’s blend of state‑aligned objectives and criminal motives demonstrates how non‑state actors can harness LLMs for sophisticated, low‑cost attacks. Security researchers warn that the group’s use of AI for content creation and tool development raises the bar for defenders, urging the deployment of indicator‑of‑compromise (IOC) feeds and vigilant monitoring for AI‑generated phishing content.
The group’s activities illustrate a growing trend in cyber warfare, where adversaries increasingly rely on generative AI to automate social engineering and malware development. Analysts recommend that organizations strengthen email filtering, employ AI‑driven threat intelligence, and conduct regular security awareness training to counter the evolving threat landscape posed by GreyVibe and similar actors.
Key changes
- GREYVIBE is a Russian‑speaking threat actor targeting Ukraine and related entities since August 2025.
- The group aligns with Kremlin state interests and uses phishing, malware, and credential‑stealing tactics.
- Custom domains mimic legitimate Ukrainian websites, making detection difficult.
- A new backdoor was deployed in late 2025 to maintain persistence on compromised systems.
- Phishing emails reference local news or political events to increase credibility.
- The group’s TTPs are consistent with other Russian‑aligned actors.
- Researchers recommend monitoring for suspicious activity and enabling MFA for critical accounts.
- The activity demonstrates ongoing threat to Ukrainian entities.