news.mlab.sh
Back to the feed
threat-intel

Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks

High
Summary

A newly identified Russia-linked threat actor, GreyVibe, is utilizing artificial intelligence to enhance the speed, scale, and sophistication of its cyberattacks, primarily targeting Ukrainian military, government, and business entities since August 2025. The group’s reliance on AI, combined with design flaws in its malware, has allowed researchers to track its activities, highlighting a concerning trend of lower-sophistication actors leveraging AI to operate more effectively. This activity is linked to the TrickBot ecosystem and raises concerns about potential expansion beyond Ukraine.

GreyVibe, described by WithSecure as a Russia-nexus group, has been actively targeting Ukrainian entities since August 2025. The group’s operations are characterized by a heavy reliance on AI, encompassing everything from creating deceptive websites and crafting lures to developing custom malware and generating post-compromise tools. This approach allows them to accelerate development and fill capability gaps, complicating tracking efforts. The researchers noted the use of AI tools like Ideogram AI, ChatGPT, and Google Gemini, alongside a design flaw in their LegionRelay Windows malware that facilitated monitoring.

The group employs a variety of tactics, including spear-phishing campaigns utilizing ZIP/RAR archives hosted on services like Google Drive and 4sync, alongside decoy files to initiate malware infections. A separate campaign, PrincessClub, leverages fake adult-club websites to deliver Fallspy (Android malware) and PhantomRelay/LegionRelay on Windows, utilizing fake female personas on Telegram and dating sites to lure victims. Furthermore, GreyVibe is utilizing a unique ISO builder potentially linked to the TrickBot ecosystem and UAC-0098, suggesting connections to former TrickBot members.

WithSecure believes GreyVibe’s operational ambition, fueled by AI, is a preview of how lower-sophistication actors will increasingly operate. The group’s evolving tradecraft and extensive use of AI are expected to continue diversifying and increasing the complexity of detection and attribution. Given the geopolitical context, there is a possibility of GreyVibe expanding its activity beyond Ukraine.

Read the full article at SecurityWeek