Meet GREYVIBE, the Russia-Linked Hacking Group Using AI to Target Ukraine and Still Making Rookie Mistakes
ID: 8f766f2c-fcdb-5adb-93bc-e45b9913a9f9
STIX ID: report--8f766f2c-fcdb-5adb-93bc-e45b9913a9f9
Feed Name: Security Affairs
GREYVIBE is a Russia-linked, hybrid threat actor active since 2025 that has run sustained campaigns against Ukrainian military, government, civilian, and business targets using five distinct attack chains (PhantomMail, PhantomClick, PrincessClub, DroneLink, Nebo). The group deploys custom malware (PhantomRelay, LegionRelay), Android spyware (FallSpy), and even cryptominers, leverages AI for code and content generation, and displays operational sloppiness and links to criminal networks that complicate attribution and tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
