Russia-linked threat group put ChatGPT to work from lure to payload
WithSecure says a Russia-linked group used ChatGPT, Gemini and Ideogram across phishing, malware and infrastructure work against Ukrainian targets.
Intelligence analysis by GPT-5.4 Mini
WithSecure says a previously undocumented group, GREYVIBE, used AI tools across most stages of attacks on Ukrainian military, government, civilian and business targets. The researchers say the operators also made basic security mistakes that exposed parts of their own infrastructure.
A security company says a hacker group used smart computer tools to help with almost every step of an attack. It is a bit like using a cooking app not just for one recipe, but to plan the shopping, prep the food, and clean up too.
The group still made silly mistakes. They left behind clues and used bad file names, which helped the researchers notice them.
The main lesson is that AI can help attackers work faster, but it does not make them perfect. Even with better tools, people can still trip over their own shoelaces.
Analysis
What WithSecure says it found
WithSecure says a previously undocumented group it tracks as GREYVIBE has been active since at least August 2025 and has targeted Ukrainian military, government, civilian, and business organizations. The campaign used spear-phishing emails, fake CAPTCHA pages, and bogus adult-club websites tied to Ukraine to trick victims into installing malware.
Where AI fits in
The researchers say they found strong evidence that the group used OpenAI's ChatGPT, Google's Gemini, and Ideogram AI throughout the operation. According to the report, those tools were used for lure creation, malware development, infrastructure setup, obfuscation tooling, and post-compromise activity. WithSecure says the use of generative AI looked operationally integrated rather than like one-off experimentation.
What that means in practice
The report argues the crew appears to be using AI to fill skill gaps and move faster. At the same time, its operators still made obvious mistakes: they uploaded malware to public services and left behind development artifacts with names such as letsrollboyos, totallyunsus, and cuteuwu.
The bigger point
WithSecure says flaws in the LegionRelay malware, which it suspects was built with LLM help, exposed parts of the backend and let the researchers watch activity for an extended period. The story lands in the middle of a broader industry argument over whether AI will produce elite attackers or mostly make existing operators faster. This case points to the second outcome: more automation, but not necessarily more discipline.
Key points
- WithSecure says GREYVIBE used ChatGPT, Gemini and Ideogram across multiple stages of its campaign.
- The activity targeted Ukrainian military, government, civilian and business organizations since at least August 2025.
- Researchers say the group used phishing, fake CAPTCHA pages and fake websites to deliver malware.
- The operators made basic mistakes, including exposing artifacts and uploading malware to public services.
- A malware flaw reportedly let researchers observe parts of GREYVIBE's backend infrastructure.



