WithSecure has uncovered a likely Russian threat cluster called GreyVibe that has been targeting Ukrainian military, government, and civilian organizations since at least August 2025. The group uses AI tools including ChatGPT, Google Gemini, and Ideogram AI to generate convincing phishing lures and develop custom malware. Attack chains include spear-phishing (PhantomMail), fake CAPTCHA pages (PhantomClick), fake adult dating sites delivering Android spyware (PrincessClub), fake military charity sites (DroneLink), and fake Russian military login pages (Nebo). Custom malware includes LegionRelay and PhantomRelay PowerShell RATs and FallSpy Android spyware. Researchers believe GreyVibe may involve former cybercriminals operating with state-directed tasking, based on links to ex-TrickBot members and atypical operational security practices. IoCs are publicly available via WithSecure's GitHub.

4m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
45 Impressions