GREYVIBE is a previously undocumented Russia-linked cyber espionage threat actor active since at least August 2025 and primarily focused on Ukraine and Ukraine-related entities. Its targeting has included military, government, civilian, and business organizations, with victimology and operational objectives aligning closely with Russian intelligence interests in the context of the Russia-Ukraine war. Available reporting also indicates the operators are Russian-speaking and work broadly in the Moscow time zone. The group uses a hybrid tradecraft model that combines espionage objectives with behaviors associated with the broader cybercrime ecosystem. GREYVIBE has been assessed as low-to-moderately sophisticated rather than a highly mature state operator, but it has sustained multiple parallel campaigns and shown adaptability in delivery, malware development, and social engineering. Indicators of cybercrime adjacency include overlap with tooling or delivery patterns seen in unrelated criminal activity, occasional deployment of cryptocurrency mining components, immature development artifacts, and operational security mistakes. GREYVIBE is notable for systematic use of generative AI and large language models across much of its operational lifecycle. Reported use of ChatGPT, Google Gemini, and Ideogram AI spans lure creation, image generation, malware and loader development, obfuscation, infrastructure setup, and post-compromise command generation. This AI-assisted workflow appears to have helped the group accelerate development, localize and tailor lures, rotate code structures, and compensate for capability gaps, while also introducing coding and design flaws that exposed parts of its backend and tooling. Observed intrusion activity has been organized into several named attack chains, including PhantomMail, PhantomClick, PrincessClub, DroneLink, and Nebo. Delivery methods have included spear-phishing with archive-based payloads, fake CAPTCHA or verification pages in ClickFix-style social engineering, fraudulent charity-themed sites, and fake adult-themed websites supported by Telegram-based persona building. These campaigns have relied on decoy documents, scripted loaders, and custom obfuscators to initiate infection and reduce straightforward detection. Associated malware families include PhantomRelay, LegionRelay, and FallSpy. PhantomRelay is a PowerShell-based remote access tool used for host profiling, command execution, and persistent access. LegionRelay is a lightweight PowerShell-based remote access implant used for file theft, screenshot capture, browser and messaging data theft, and enabling remote access workflows. FallSpy is an Android spyware implant used to harvest sensitive device and user information. Reporting also notes that some lure infrastructure evolved beyond malware delivery into direct collection mechanisms, including audio and video capture features, suggesting overlap between cyber collection and human intelligence-style targeting. GREYVIBE has also demonstrated repeated operational security weaknesses, including exposing backend functionality through malware design flaws and leaving immature development traces. These shortcomings, combined with its AI-enabled scaling and cybercrime-adjacent characteristics, make GREYVIBE a hybrid Russia-nexus threat actor that blurs the boundary between state-aligned espionage and criminal tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted Ukraine-related organizations while incorporating generative AI and LLMs into operations.
Russia-linked cyber espionage group using AI tools to help build malware, spin up infrastructure, and craft lures for attacks on Ukrainian targets.
Cyber espionage operations targeting Ukrainian entities and Eastern Europe using multi-vector social engineering, phishing, fake verification pages, romance lures, and custom implants for intelligence collection.
Conducting AI-assisted attack campaigns against Ukrainian military, government, civilian, and business organizations using custom obfuscators, fake content, loaders, and malware across multiple parallel attack chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.