GREYVIBE Threat Actors Use ChatGPT and Google Gemini to Scale Cyberattack Operations
ID: b754112a-5965-5f46-a00a-57478ed75067
STIX ID: report--b754112a-5965-5f46-a00a-57478ed75067
Feed Name: GBHackers
GREYVIBE, a Russia-linked threat group active since at least August 2025, has systematically used generative AI (ChatGPT, Google Gemini, Ideogram AI) to scale multi-vector campaigns—PhantomMail, PhantomClick, and PrincessClub—delivering PowerShell- and WebSocket-based RATs (LegionRelay, PhantomRelay) and Android spyware (FallSpy) via phishing, fake CAPTCHA pages, and malicious sites; the group leverages custom obfuscators (DAYLIGHT, TEASOUP) and AI-assisted development to accelerate lure creation and infrastructure setup, complicating detection and attribution, and defenders are advised to strengthen email filtering, monitor unusual command execution, and apply behavior-based detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
