Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
EtherRAT Spreads via Scheduled Tasks in Compromised Windows Domains
August 5, 2026
7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen
August 5, 2026
Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds
August 5, 2026
Home/CyberSecurity News/GreyVibe Hackers Use ChatGPT, Google Gemini to Power Cyberattacks
CyberSecurity News

GreyVibe Hackers Use ChatGPT, Google Gemini to Power Cyberattacks

Key Takeaways A newly tracked threat group, GREYVIBE, is extensively leveraging generative AI tools like ChatGPT and Google Gemini to enhance its cyberattack capabilities. The group’s...

Jennifer sherman
Jennifer sherman
May 30, 2026 4 Min Read
60 0

Key Takeaways

  • A newly tracked threat group, GREYVIBE, is extensively leveraging generative AI tools like ChatGPT and Google Gemini to enhance its cyberattack capabilities.
  • The group’s operations, active since at least August 2025, primarily target Ukrainian government, military, and civilian entities.
  • GREYVIBE employs sophisticated multi-vector attacks, including spear-phishing, fake CAPTCHA pages, and deceptive websites to distribute malware such as FallSpy and PhantomRelay.
  • Despite using advanced AI, the group exhibits some operational security weaknesses, which WithSecure researchers exploited to monitor their activities.
  • While not definitively attributed, evidence strongly suggests GREYVIBE aligns with Russian state interests, focusing on intelligence gathering related to the Russia-Ukraine conflict.

AI-Powered Cyber Campaigns Target Ukraine

A previously uncataloged threat actor, identified as GREYVIBE, has significantly intensified its cyberattack campaigns by integrating generative artificial intelligence tools such as ChatGPT and Google Gemini. These AI-powered operations, which began in at least August 2025, are predominantly directed at Ukrainian government, military, and civilian sectors, illustrating a concerning evolution in modern cyber warfare where AI plays a central role.

Table Of Content

  • Key Takeaways
  • AI-Powered Cyber Campaigns Target Ukraine
  • GREYVIBE’s Multi-Vector Attack Strategy
  • Generative AI at the Core of Operations
  • Malware Toolkit and Operational Maturity
  • What You Should Do

WithSecure researchers were the first to identify GREYVIBE as a distinct threat group. Their analysis revealed consistent patterns in infrastructure, tools, and operational methodologies across multiple attack waves. Although no definitive state attribution has been made, the group’s activities show strong alignment with Russian state interests, particularly in intelligence collection objectives relevant to the ongoing conflict with Ukraine. Supporting evidence includes the presence of Russian-language artifacts, operational timings consistent with the Moscow time zone, and targeting profiles focused on Ukrainian institutions.

GREYVIBE’s Multi-Vector Attack Strategy

GREYVIBE employs a diverse and adaptive attack methodology. Their campaigns frequently involve spear-phishing emails, convincing fake CAPTCHA verification pages, and fraudulent websites designed to distribute various malware payloads. In their spear-phishing operations, the attackers often impersonate legitimate Ukrainian government agencies, distributing malicious archives through popular cloud services like Google Drive. These archives typically execute decoy documents while covertly initiating infection chains via custom loaders.

Another prominent tactic involves crafting fake CAPTCHA pages. These pages are engineered to trick unsuspecting victims into executing malicious commands under the guise of completing a verification step. Furthermore, the group operates deceptive “adult club” websites, specifically targeting individuals in Ukraine, particularly military personnel. These platforms serve a dual purpose: they deliver malware like FallSpy for Android and PhantomRelay for Windows, and they facilitate social engineering through fake personas on messaging platforms such as Telegram.

Generative AI at the Core of Operations

A critical revelation from the WithSecure report is GREYVIBE’s systematic application of generative AI across nearly every phase of their attack lifecycle. Tools such as ChatGPT, Google Gemini, and Ideogram AI have reportedly been used to craft compelling phishing lures, develop components for their malware, and support post-compromise activities. Researchers observed AI-generated code patterns within obfuscators and loaders, specifically named DAYLIGHT and TEASOUP, as well as in the development of LegionRelay, a custom PowerShell-based remote access trojan.

This AI-assisted approach appears to compensate for any potential technical limitations within the group, simultaneously accelerating their development cycles. It also helps reduce reliance on previously used code, making traditional attribution methods more challenging. However, this dependence on AI has also introduced vulnerabilities. As WithSecure identified, LegionRelay contained design weaknesses that exposed its backend functionality, enabling researchers to monitor the attackers’ activities over an extended period.

Malware Toolkit and Operational Maturity

GREYVIBE’s malware arsenal includes PhantomRelay, a modular Remote Access Trojan (RAT) that uses WebSockets for command and control, and FallSpy, an Android spyware designed to exfiltrate sensitive data such as contacts, location information, and device specifics. LegionRelay further extends their capabilities, allowing for file exfiltration, screenshot capture, and the theft of messaging application data.

Despite the sophistication brought by AI, GREYVIBE exhibits certain signs of operational immaturity. Researchers noted instances of poor operational security practices, including the uploading of test samples to public platforms and inconsistencies in their tooling. Concurrently, overlaps with known cybercrime infrastructure suggest potential connections to former or active cybercriminal actors, hinting at a hybrid threat model. The emergence of GREYVIBE underscores how generative AI is profoundly reshaping the threat landscape. By lowering technical barriers and enabling rapid tool development, AI is empowering even moderately skilled actors to conduct complex cyber operations, thereby complicating detection, attribution, and defense efforts for cybersecurity professionals worldwide.

What You Should Do

  • Implement advanced email filtering and anti-phishing solutions to detect and block malicious spear-phishing attempts.
  • Educate users on identifying sophisticated social engineering tactics, including fake CAPTCHA pages and deceptive websites.
  • Deploy robust endpoint detection and response (EDR) solutions to identify and mitigate malware like FallSpy, PhantomRelay, and LegionRelay.
  • Regularly update and patch all operating systems, applications, and security software to protect against known vulnerabilities.
  • Monitor network traffic for unusual activity, especially WebSocket-based communications that could indicate RAT activity.
  • Advise military personnel and government employees to exercise extreme caution with unsolicited communications and suspicious websites, particularly those targeting personal interests.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Google Chrome Device-Bound Sessions Go GA to Prevent Account Takeovers

Next Post

Pentest Swarm AI Tool Exposes Critical Vulnerabilities in Nmap, SQLMap, Burp, Metasploit

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
AI Agents Mythos 5, GPT-5.6-Sol Escaped Cybersecurity Sandbox to Attack Real Systems
August 5, 2026
CISA Warns of Apache Tomcat Encryption Flaw Actively Exploited
August 5, 2026
Critical RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us