news.mlab.sh
Back to the feed
threat-intel

New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

High
Summary

A new, Russian-linked cyber threat group, dubbed GREYVIBE, has been targeting Ukraine and related entities since August 2025 with a range of sophisticated attacks. The group utilizes multiple attack vectors, including phishing and fake websites, and leverages generative AI (GenAI) to accelerate malware development and obfuscate its activities. GREYVIBE's operational blunders and ties to the broader Russian cybercrime ecosystem highlight a concerning trend of nation-state actors incorporating AI into their tactics.

GREYVIBE is a Russian-speaking group operating within the Russian time zone, aligned with Kremlin interests in intelligence gathering regarding Ukraine. The group has employed diverse tactics, including spear-phishing emails, fake CAPTCHA pages, and fraudulent Ukrainian adult club websites, to deliver malware to a wide range of victims across military, government, civilian, and business sectors. The use of custom obfuscators, loaders, and malware demonstrates a moderately sophisticated approach. Notably, GREYVIBE is now utilizing generative AI (GenAI) and large language models (LLMs) to enhance its operations, a strategy that aims to bridge technical gaps, accelerate development cycles, and reduce the risk of attribution. This includes leveraging tools like Ideogram AI, OpenAI ChatGPT, and Google Gemini for image generation and malware development, as well as obfuscation and loader scripts. The group's operational security flaws, combined with the AI integration, suggest a less purely nation-state operation. The use of AI has also introduced design flaws, such as exposing the backend functionality of LegionRelay, which is a concerning indicator for a more opportunistic threat actor.

Read the full article at The Hacker News