GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
GreyVibe, a threat actor likely linked to Russia, has been conducting cyber espionage campaigns targeting Ukrainian organizations since August 2025, utilizing a diverse range of custom malware and AI-generated lures. The group employs tools like ChatGPT and Gemini to create realistic phishing campaigns and obfuscated malware, exhibiting a level of sophistication that suggests potential involvement of cybercriminals. This activity highlights a complex threat landscape with potential ties to both state-sponsored and criminal actors.
GreyVibe’s cyberespionage campaign, discovered by WithSecure in January 2024, focuses on Ukrainian entities and appears to align with Russian state interests. The group leverages a suite of malware, including PhantomMail, PhantomClick, PrincessClub, DroneLink, and Nebo, each designed for specific attack chains. Notably, the campaign utilizes AI tools like ChatGPT and Google Gemini to generate highly convincing lures, mimicking Ukrainian government, emergency, and telecom entities. This approach demonstrates a shift towards more sophisticated and adaptable attack methods. The research indicates a potential blurring of lines between state-sponsored and criminal actors, with evidence suggesting the inclusion of former TrickBot members and the deployment of a cryptocurrency miner.