Threats · 108 days ago
GREYVIBE matters because AI is helping a Russia-linked espionage actor scale faster without fitting the old model of a clean state team. The real change is the blur: WithSecure ties the group to both Kremlin-aligned intelligence work and the broader Russian cybercrime ecosystem, so motive and tradecraft are harder to separate.
WithSecure says GREYVIBE has hit Ukraine and Ukraine-related entities since at least August 2025, with targets across military, government, civilian, and business sectors. The group has used spear-phishing, fake CAPTCHA pages, and bogus websites to get victims to run commands, and it has paired those lures with custom obfuscators, loaders, and malware built with help from generative AI and LLMs.
That mix makes attribution slower and behavioral detection more useful than simple actor labels or blocklists. The campaign also shows how “prove you’re human” prompts can become the delivery step itself, which is a problem for organizations that train users to spot phishing but not lure-driven click-to-run traps.
4 sources covering this story
New Russia-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks
GREYVIBE targeted Ukraine since August 2025 using AI-assisted malware campaigns, increasing espionage capabilities and attribution challenges.
Russia-linked threat group put ChatGPT to work from lure to payload
Researchers say 'GREYVIBE' crew used AI tools throughout a campaign targeting Ukrainian military and government
Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks
Researchers warn GreyVibe’s extensive use of ChatGPT, Gemini, and other AI tools offers a glimpse into how future cybercriminal and state-aligned groups will operate.
GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
A likely Russian threat cluster tracked as GreyVibe has been targeting Ukrainian entities with AI-generated lures and a rich set of custom malware tools.
Part of the PlainSec briefing for 2026-05-30