GreyVibe Hackers Use ChatGPT, Google Gemini to Power Cyberattacks
Key Takeaways A newly tracked threat group, GREYVIBE, is extensively leveraging generative AI tools like ChatGPT and Google Gemini to enhance its cyberattack capabilities. The group’s...
Key Takeaways
- A newly tracked threat group, GREYVIBE, is extensively leveraging generative AI tools like ChatGPT and Google Gemini to enhance its cyberattack capabilities.
- The group’s operations, active since at least August 2025, primarily target Ukrainian government, military, and civilian entities.
- GREYVIBE employs sophisticated multi-vector attacks, including spear-phishing, fake CAPTCHA pages, and deceptive websites to distribute malware such as FallSpy and PhantomRelay.
- Despite using advanced AI, the group exhibits some operational security weaknesses, which WithSecure researchers exploited to monitor their activities.
- While not definitively attributed, evidence strongly suggests GREYVIBE aligns with Russian state interests, focusing on intelligence gathering related to the Russia-Ukraine conflict.
AI-Powered Cyber Campaigns Target Ukraine
A previously uncataloged threat actor, identified as GREYVIBE, has significantly intensified its cyberattack campaigns by integrating generative artificial intelligence tools such as ChatGPT and Google Gemini. These AI-powered operations, which began in at least August 2025, are predominantly directed at Ukrainian government, military, and civilian sectors, illustrating a concerning evolution in modern cyber warfare where AI plays a central role.
Table Of Content
WithSecure researchers were the first to identify GREYVIBE as a distinct threat group. Their analysis revealed consistent patterns in infrastructure, tools, and operational methodologies across multiple attack waves. Although no definitive state attribution has been made, the group’s activities show strong alignment with Russian state interests, particularly in intelligence collection objectives relevant to the ongoing conflict with Ukraine. Supporting evidence includes the presence of Russian-language artifacts, operational timings consistent with the Moscow time zone, and targeting profiles focused on Ukrainian institutions.
GREYVIBE’s Multi-Vector Attack Strategy
GREYVIBE employs a diverse and adaptive attack methodology. Their campaigns frequently involve spear-phishing emails, convincing fake CAPTCHA verification pages, and fraudulent websites designed to distribute various malware payloads. In their spear-phishing operations, the attackers often impersonate legitimate Ukrainian government agencies, distributing malicious archives through popular cloud services like Google Drive. These archives typically execute decoy documents while covertly initiating infection chains via custom loaders.
Another prominent tactic involves crafting fake CAPTCHA pages. These pages are engineered to trick unsuspecting victims into executing malicious commands under the guise of completing a verification step. Furthermore, the group operates deceptive “adult club” websites, specifically targeting individuals in Ukraine, particularly military personnel. These platforms serve a dual purpose: they deliver malware like FallSpy for Android and PhantomRelay for Windows, and they facilitate social engineering through fake personas on messaging platforms such as Telegram.
Generative AI at the Core of Operations
A critical revelation from the WithSecure report is GREYVIBE’s systematic application of generative AI across nearly every phase of their attack lifecycle. Tools such as ChatGPT, Google Gemini, and Ideogram AI have reportedly been used to craft compelling phishing lures, develop components for their malware, and support post-compromise activities. Researchers observed AI-generated code patterns within obfuscators and loaders, specifically named DAYLIGHT and TEASOUP, as well as in the development of LegionRelay, a custom PowerShell-based remote access trojan.
This AI-assisted approach appears to compensate for any potential technical limitations within the group, simultaneously accelerating their development cycles. It also helps reduce reliance on previously used code, making traditional attribution methods more challenging. However, this dependence on AI has also introduced vulnerabilities. As WithSecure identified, LegionRelay contained design weaknesses that exposed its backend functionality, enabling researchers to monitor the attackers’ activities over an extended period.
Malware Toolkit and Operational Maturity
GREYVIBE’s malware arsenal includes PhantomRelay, a modular Remote Access Trojan (RAT) that uses WebSockets for command and control, and FallSpy, an Android spyware designed to exfiltrate sensitive data such as contacts, location information, and device specifics. LegionRelay further extends their capabilities, allowing for file exfiltration, screenshot capture, and the theft of messaging application data.
Despite the sophistication brought by AI, GREYVIBE exhibits certain signs of operational immaturity. Researchers noted instances of poor operational security practices, including the uploading of test samples to public platforms and inconsistencies in their tooling. Concurrently, overlaps with known cybercrime infrastructure suggest potential connections to former or active cybercriminal actors, hinting at a hybrid threat model. The emergence of GREYVIBE underscores how generative AI is profoundly reshaping the threat landscape. By lowering technical barriers and enabling rapid tool development, AI is empowering even moderately skilled actors to conduct complex cyber operations, thereby complicating detection, attribution, and defense efforts for cybersecurity professionals worldwide.
What You Should Do
- Implement advanced email filtering and anti-phishing solutions to detect and block malicious spear-phishing attempts.
- Educate users on identifying sophisticated social engineering tactics, including fake CAPTCHA pages and deceptive websites.
- Deploy robust endpoint detection and response (EDR) solutions to identify and mitigate malware like FallSpy, PhantomRelay, and LegionRelay.
- Regularly update and patch all operating systems, applications, and security software to protect against known vulnerabilities.
- Monitor network traffic for unusual activity, especially WebSocket-based communications that could indicate RAT activity.
- Advise military personnel and government employees to exercise extreme caution with unsolicited communications and suspicious websites, particularly those targeting personal interests.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.