GREYVIBE Hackers Use ChatGPT and Gemini to Power Cyberattacks
ID: 8ac7f0ee-e7b4-5dcb-8bf0-88760a3ba7ca
STIX ID: report--8ac7f0ee-e7b4-5dcb-8bf0-88760a3ba7ca
Feed Name: Cyber Press
WithSecure researchers detail GREYVIBE, a Russia-aligned threat group using generative AI (ChatGPT, Gemini, Ideogram) to accelerate development of phishing lures, fake sites, custom malware (PowerShell RATs like LegionRelay/PhantomRelay and FallSpy Android spyware), and post-compromise tooling across multiple campaigns (PhantomMail, PhantomClick, PrincessClub, DroneLink, Nebo) targeting Ukrainian military, government, civilians, and businesses since August 2025; the group's heavy AI usage amplifies capability despite operational security flaws that have exposed parts of its backend and linked it to cybercrime ecosystems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
