WithSecure reported that a previously undocumented Russia-linked threat group, GREYVIBE, has conducted cyber espionage operations against Ukrainian military, government, civilian, and business organizations since at least August 2025. The actor reportedly used ChatGPT, Google Gemini, and Ideogram AI across multiple stages of its operations, including phishing-lure creation, malware and loader development, obfuscation, infrastructure setup, and post-compromise activity. Delivery methods included spear-phishing emails, fake CAPTCHA pages, fraudulent Ukrainian adult-club websites, and charity-themed lure sites.
Researchers said GREYVIBE deployed malware families including PhantomRelay, LegionRelay, and FallSpy, and assessed the operators as Russian-speaking and aligned with Kremlin intelligence interests tied to the war in Ukraine. Despite broad AI adoption, the group was described as low-to-moderately sophisticated and prone to operational security failures, including public malware uploads, exposed development artifacts, and flaws in LegionRelay that revealed parts of its backend infrastructure. Investigators also noted signs of overlap with the Russian cybercrime ecosystem, including cybercrime-linked tooling and occasional XMRig deployment, underscoring a blurred line between state-aligned espionage and criminal tradecraft.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers said GREYVIBE made repeated operational security mistakes, such as uploading malware to public services and leaving development artifacts behind. WithSecure also reported that flaws in the group's LegionRelay malware exposed parts of its backend infrastructure and enabled extended monitoring of its activity.
WithSecure assessed GREYVIBE as a previously undocumented, Russian-linked threat actor whose operators are Russian-speaking, work broadly in the Russian/Moscow time zone, and align with Kremlin intelligence interests. The report also said the group used generative AI tools including ChatGPT, Gemini, and Ideogram AI across lure creation, malware and obfuscator development, infrastructure setup, and post-compromise activity.
In March and April 2026, WithSecure observed a campaign tracked as DroneLink that overlapped operationally with PrincessClub. DroneLink used fake charity websites themed around support for the Armed Forces of Ukraine and shared command-and-control infrastructure and tooling with GREYVIBE-associated activity.
WithSecure reported that the previously undocumented threat group GREYVIBE has targeted Ukrainian military, government, civilian, business, and other Ukraine-related organizations since at least August 2025. The campaign used spear-phishing emails, fake CAPTCHA pages, fraudulent Ukrainian adult-club websites, and charity-themed lure sites to deliver malware including PhantomRelay, LegionRelay, and FallSpy.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcetheregister.com
Open sourcewithsecure.com
Open sourcelabs.withsecure.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.