logo

New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

ID: df7a5cfc-a4b6-5542-bbf9-1cc9e654740e

STIX ID: report--df7a5cfc-a4b6-5542-bbf9-1cc9e654740e

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: [email protected] (The Hacker News)

...
...

WithSecure attributes a previously undocumented Russian-speaking threat actor tracked as GREYVIBE to ongoing cyber espionage against Ukrainian and Ukraine-related targets since August 2025. GREYVIBE operates multiple campaigns (PhantomMail, PhantomClick, PrincessClub, DroneLink, Nebo) delivering RATs and spyware (PhantomRelay, LegionRelay, FallSpy), uses spear-phishing, fake CAPTCHA and lure sites, and leverages generative AI to produce images, code, obfuscation, and infrastructure; investigators note ties to the criminal ecosystem and mixed sophistication with operational security flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.