logo

GREYVIBE Threat Actors Use ChatGPT and Google Gemini to Scale Cyberattack Operations

ID: b754112a-5965-5f46-a00a-57478ed75067

STIX ID: report--b754112a-5965-5f46-a00a-57478ed75067

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Divya

...
...

GREYVIBE, a Russia-linked threat group active since at least August 2025, has systematically used generative AI (ChatGPT, Google Gemini, Ideogram AI) to scale multi-vector campaigns—PhantomMail, PhantomClick, and PrincessClub—delivering PowerShell- and WebSocket-based RATs (LegionRelay, PhantomRelay) and Android spyware (FallSpy) via phishing, fake CAPTCHA pages, and malicious sites; the group leverages custom obfuscators (DAYLIGHT, TEASOUP) and AI-assisted development to accelerate lure creation and infrastructure setup, complicating detection and attribution, and defenders are advised to strengthen email filtering, monitor unusual command execution, and apply behavior-based detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.