Russia-Linked ‘GreyVibe’ Attackers Use AI to Accelerate Cyber Operations
The emergence of GreyVibe, a previously undocumented threat actor, marks a significant development in the landscape of cyber threats. Identified by cybersecurity researchers as a group with ties to Russian-speaking operators, GreyVibe has been active since August 2025, primarily targeting Ukrainian military, government, civilian, and business entities. This focus aligns closely with Russian state interests, raising questions about the group’s operational motives and affiliations.
Attribution and Operational Ambiguity
Researchers from WithSecure have attributed GreyVibe to Russian-speaking individuals operating within the Moscow time zone. However, there remains uncertainty regarding whether the group functions as a cybercriminal organization, a nation-state actor, or a hybrid of both. This ambiguity complicates the understanding of their operational structure and objectives.
The group’s activities have been characterized by a notable use of Internet slang in their early-stage development artifacts, suggesting that some members may not fit the profile of elite state operators. Naming conventions such as ‘letsrollboyos’ and ‘totallyunsus’ indicate a less formal approach, which contrasts with the expectations of highly skilled threat actors.
AI Utilization Across Operations
One of the defining features of GreyVibe’s operations is its extensive use of artificial intelligence (AI) throughout various phases, including the creation of fake websites, crafting lures, and developing custom malware. This reliance on AI is not unique to GreyVibe; however, the group’s approach raises questions about their sophistication. While they have employed advanced AI tools like Ideogram AI, ChatGPT, and Google Gemini, they have also introduced design flaws in their LegionRelay Windows malware. Such errors are typically not associated with elite actors, allowing researchers to monitor GreyVibe’s activities over an extended period.
Mohammad Kazem Hassan Nejad, a senior threat intelligence researcher at WithSecure, noted that GreyVibe’s distinguishing factor lies not in raw technical skill but in operational ambition. The group leverages generative AI to enhance its capabilities, filling gaps and creating a fresh operational profile that complicates tracking and attribution.
Diverse Attack Strategies
GreyVibe’s initial attack vectors include a variety of spear-phishing campaigns, with at least six distinct approaches identified. These campaigns direct victims to ZIP or RAR archives hosted on third-party file-sharing services, such as Google Drive. Once accessed, these files launch decoy programs while simultaneously initiating a PhantomRelay malware infection in the background.
In another campaign dubbed “PrincessClub,” GreyVibe utilized fake adult-club websites to distribute Fallspy (Android malware) alongside PhantomRelay or LegionRelay on Windows systems. Victims were further enticed by fake female personas on platforms like Telegram and dating sites, illustrating the group’s strategic use of social engineering.
Evolving Tradecraft and Future Implications
The extensive use of AI not only compensates for GreyVibe’s operational gaps but also minimizes historical backlinks to previous activities. While it remains unclear whether the group has been tracked under a different name in the past, WithSecure has found no evidence to suggest this.
The researchers have identified a unique ISO builder potentially linked to the TrickBot ecosystem and the UAC-0098 activity cluster, which may involve former TrickBot members previously observed targeting Ukraine. This connection underscores the evolving nature of cyber threats and the potential for collaboration among various threat actors.
GreyVibe remains active, and its members are still unidentified. As the group continues to refine its AI capabilities, experts anticipate that its tradecraft will evolve, increasing the complexity of detection, tracking, and attribution efforts. The potential for GreyVibe to expand its operational focus beyond Ukraine raises significant concerns, particularly given the current geopolitical climate.
Conclusion
The rise of GreyVibe exemplifies the changing dynamics of cyber threats, particularly in the context of geopolitical tensions. As the group continues to leverage AI to enhance its operational capabilities, the cybersecurity community must remain vigilant in monitoring its activities and adapting to the evolving landscape of cyber warfare.
For further insights into the implications of AI in cybersecurity, refer to the original reporting source: SecurityWeek.
Keep reading for the latest cybersecurity developments, threat intelligence and breaking updates from across the Middle East.


