logo

Russia-linked threat group put ChatGPT to work from lure to payload

ID: ea3dc191-4f2c-5f68-a3e8-e032633cc6dd

STIX ID: report--ea3dc191-4f2c-5f68-a3e8-e032633cc6dd

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-05-29

Date Updated: 2026-05-30

...
...

Researchers at WithSecure attributed an active Russia-linked espionage campaign, tracked as GREYVIBE, against Ukrainian military, government, civilian, and business targets since at least August 2025; the group systematically used generative AI (ChatGPT, Gemini, Ideogram) across multiple operational stages to craft lures, create and obfuscate malware (including LegionRelay), and build infrastructure, though operational security mistakes and design flaws exposed parts of their backend and allowed extended monitoring by researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.