logo

GREYVIBE Hackers Leverage ChatGPT and Google Gemini to Fuel Cyberattacks

ID: 1e037018-eedb-5c2e-8fb3-c360ea3036ae

STIX ID: report--1e037018-eedb-5c2e-8fb3-c360ea3036ae

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-30

Date Updated: 2026-05-30

Author: Abinaya

...
...

GREYVIBE is an emergent threat actor active since at least August 2025 that targets Ukrainian government, military, and civilian sectors using spear-phishing, fake CAPTCHA pages, and deceptive websites to deliver modular malware (PhantomRelay RAT, LegionRelay, FallSpy Android spyware). The group systematically leverages generative AI (ChatGPT, Google Gemini, Ideogram) to author phishing lures, obfuscators, and malware components—accelerating development and complicating attribution—while operational errors have exposed some backend functionality allowing researchers limited visibility into the actor's activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.