New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks
WithSecure says GREYVIBE has been hitting Ukraine since at least August 2025 using phishing, fake sites, and AI-assisted tooling. The group appears to sit between cybercrime and state-linked activity.
Intelligence analysis by GPT-5.4 Mini
WithSecure attributes a previously undocumented threat actor, GREYVIBE, to persistent campaigns against Ukraine and Ukraine-related targets. The group uses multiple lure types, custom loaders, Android spyware, PowerShell RATs, and AI tools to speed malware development and infrastructure work.
A hacking group called GREYVIBE has been sneaking into computers in Ukraine using fake emails, fake websites, and tricky download files. Some of its tricks even try to fool people into typing commands themselves.
Think of it like a thief using many different disguises instead of just one mask. That makes the thief harder to spot and easier to keep trying new tricks.
The report says the group may also be using AI tools to work faster and build its malware. But those shortcuts may have made mistakes easier to find, which helped researchers learn how the attacks work.
Analysis
What WithSecure found
WithSecure says GREYVIBE has been conducting ongoing attacks against Ukraine and Ukraine-related organizations since at least August 2025. The victim set spans military, government, civilian, and business targets, and the company assesses the group as Russian-speaking, operating broadly in the Russian time zone, and aligned with Kremlin interests in intelligence gathering.
How the attacks work
The group has used several delivery chains. One, called PhantomMail, sends spear-phishing emails with links to malicious ZIP or RAR archives hosted on Google Drive and 4sync. Those archives contain JavaScript loaders that open a decoy document and then launch PhantomRelay, a PowerShell-based RAT that can profile a host and run scripts and Windows commands.
Another chain, PhantomClick, uses ClickFix-style fake CAPTCHA pages on bogus domains pretending to be Zoom and LAPAS. These pages trick users into running commands that start a PhantomRelay infection. A third chain, PrincessClub, uses fake Ukrainian adult-club websites to deliver FallSpy on Android and PhantomRelayV1 or LegionRelay on Windows. Later versions of those lure sites added a WebRTC live-call feature to capture audio and video.
Why AI matters here
WithSecure says GREYVIBE appears to have used GenAI and LLMs, including Ideogram AI, ChatGPT, and Gemini, to generate images, help build LegionRelay, and support obfuscation, loaders, backend infrastructure, and post-compromise commands. The company says AI likely helps the group compensate for technical gaps and move faster. At the same time, that reliance seems to have introduced flaws in LegionRelay that exposed backend functionality.
Attribution remains messy
WithSecure says GREYVIBE also shows ties to the wider Russian cybercrime ecosystem, based on factors such as possible use of an ISO builder linked to TrickBot and UAC-0098, PhantomRelay variants appearing in unrelated crime clusters, early test uploads to VirusTotal, slang-like artifact names, and XMRig deployment on a small number of infected hosts. The firm calls the group a grey area between cybercrime and state-affiliated activity, making attribution harder.
Key points
- WithSecure says GREYVIBE has targeted Ukraine and Ukraine-related entities since at least August 2025.
- The group uses phishing, fake CAPTCHA pages, and fraudulent websites to deliver malware.
- Its toolkit includes PhantomRelay, LegionRelay, FallSpy, and other custom loaders and obfuscators.
- WithSecure says GREYVIBE appears to use AI tools to speed malware and infrastructure development.
- The company says the group sits in a grey area between cybercrime and state-linked activity.



