AI Blurs the Line in GREYVIBE Espionage

GREYVIBE matters because AI is helping a Russia-linked espionage actor scale faster without fitting the old model of a clean state team. The real change is the blur: WithSecure ties the group to both Kremlin-aligned intelligence work and the broader Russian cybercrime ecosystem, so motive and tradecraft are harder to separate. WithSecure says GREYVIBE has hit Ukraine and Ukraine-related entities since at least August 2025, with targets across military, government, civilian, and business sectors. The group has used spear-phishing, fake CAPTCHA pages, and bogus websites to get victims to run commands, and it has paired those lures with custom obfuscators, loaders, and malware built with help from generative AI and LLMs. That mix makes attribution slower and behavioral detection more useful than simple actor labels or blocklists. The campaign also shows how “prove you’re human” prompts can become the delivery step itself, which is a problem for organizations that train users to spot phishing but not lure-driven click-to-run traps.

Part of the PlainSec briefing for 2026-05-30

Sources