3 Sources
[1]
Russia-linked threat group put ChatGPT to work from lure to payload
Researchers say 'GREYVIBE' crew used AI tools throughout a campaign targeting Ukrainian military and government Russia-linked cyber espionage crews appear to be using AI tools to help build malware, spin up infrastructure, and craft lures for attacks on Ukrainian targets. Researchers at
[2]
GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
A likely Russian threat group tracked as GreyVibe has been using AI-generated lures and a rich set of custom malware tools to target entities in the military, government, civilian, and business sectors. The cyberespionage campaign has been active since at least August 2025 and appears to align
[3]
New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks
A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025. GREYVIBE, per WithSecure, is assessed to be a Russian-speaking group operating broadly in the Russian time zone,
Share
Copy Link
A Russia-linked threat group called GREYVIBE has been using ChatGPT, Google Gemini, and Ideogram AI throughout cyberattacks targeting Ukrainian military and government entities since August 2025. WithSecure researchers found the group integrated AI tools across malware development, infrastructure setup, and lure creation—but operational security mistakes exposed their backend systems.
A previously undocumented Russia-linked threat group tracked as GREYVIBE has been conducting AI-powered cyberattacks against Ukraine since at least August 2025, according to researchers at WithSecure
1
. The campaign targets military, government, civilian, and business organizations, with the threat actor using OpenAI's ChatGPT, Google Gemini, and Ideogram AI across nearly every stage of operations2
. WithSecure found "strong evidence" that GREYVIBE systematically relied on AI tools for lure development, malware creation, infrastructure setup, obfuscation tooling, and post-compromise activity—marking what researchers describe as "operationally integrated rather than isolated or experimental" use of generative AI and large language models1
.
Source: The Register
The cyber espionage operation aligns with Russian intelligence interests, with researchers linking the activity to Russian-speaking operators in the Moscow time zone
3
. Mohammad Kazem Hassan Nejad, senior threat intelligence researcher at WithSecure, noted that "GREYVIBE appears to use AI not only for isolated development tasks, but across multiple operational phases. This likely enables the group to compensate for capability gaps, accelerate development cycles, and potentially reduce historical backlinks to prior activity"1
.GREYVIBE has deployed several distinct attack chains against Ukrainian targets. The PhantomMail campaign uses spear-phishing emails delivering malicious ZIP or RAR archives via Google Drive and 4sync links, with decoy PDFs or fake errors while deploying malware
2
. Observed lures impersonated Ukrainian government, emergency, telecom, and energy entities. The PhantomClick vector employs fake CAPTCHA pages disguised as Zoom and LAPAS sites to trick victims into running self-infecting commands through fake Cloudflare verification prompts2
.
Source: Hacker News
The PrincessClub campaign uses fake Ukrainian adult and dating websites to deliver FallSpy Android spyware and PhantomRelay or LegionRelay Windows malware
3
. Operators used fake female Telegram personas and later added WebRTC-based live calls capable of capturing victim audio and video. The DroneLink campaign deployed fake Ukrainian military charity websites themed around FPV drones and UAVs, while the Nebo campaign used fake Russian military communications login pages likely designed to deceive Ukrainian military personnel2
.The diversity and quality of these lures stem from using multiple AI tools to generate detailed and realistic content
2
. Malware development with AI extends to custom obfuscators including LOOKVALPS, LOOKVALJS, DAYLIGHT, and TEASOUP, all likely developed with LLM assistance. LegionRelay, a PowerShell-based remote access trojan, supports file theft, screenshot capturing, browser credential theft, Telegram and WhatsApp data exfiltration, and RDP access setup2
. PhantomRelay, another PowerShell RAT, enables system fingerprinting, dynamic script loading, and command execution2
.Despite the AI tooling, GREYVIBE repeatedly made operational security mistakes. The group uploaded malware to public services and left behind development artifacts with names including "letsrollboyos," "totallyunsus," and "cuteuwu"
1
. Design flaws in LegionRelay, suspected to be developed with LLM assistance, exposed parts of its backend infrastructure and allowed researchers to monitor activity over an extended period1
. WithSecure characterized GREYVIBE as a "low-to-moderately sophisticated group" lacking the operational discipline typically associated with mature nation-state actors2
.Related Stories
Evidence suggests GREYVIBE may include current or former cybercriminal actors. PhantomRelay variants appeared across seemingly unrelated cybercrime activity clusters, including a Microsoft Teams voice phishing campaign between July 2025 and February 2026
3
. Early test samples used a unique ISO builder associated with former TrickBot members and UAC-0098 that targeted Ukraine at the start of the Russian invasion2
. Additionally, a cryptocurrency miner was deployed on some victim machines2
.
Source: BleepingComputer
Researchers remain uncertain "whether former or current cybercriminal members have been absorbed into a state-backed group, operate independently but with state-directed tasking, or have formed a hybrid team involving state-affiliated and cybercriminal members"
2
. This case illustrates how AI tools enable less sophisticated actors to accelerate operations and bridge capability gaps, though they don't eliminate fundamental security mistakes. As ChatGPT in cyberattacks becomes more prevalent, defenders should monitor for AI-generated patterns while traditional clustering methods based on stable technical artifacts may become less reliable over time3
.Summarized by
Navi
[2]
19 Dec 2025•Technology

12 Feb 2026•Technology

31 Jan 2025•Technology

1
Technology

2
Technology

3
Science and Research
