# Russian Threat Group GreyVibe Weaponizes ChatGPT and Gemini in Sophisticated Cyberespionage Campaign


A sophisticated Russian-linked threat actor tracked as GreyVibe has been leveraging generative AI tools—including OpenAI's ChatGPT, Google Gemini, and Ideogram—to craft highly convincing phishing lures and develop custom malware, targeting military, government, and civilian organizations with a focus on Ukrainian entities. Security researchers at WithSecure uncovered the extensive campaign in January 2026, revealing a complex operation that has been active since at least August 2025 and demonstrates how modern adversaries are weaponizing publicly available AI to scale their social engineering capabilities.


The campaign represents a significant inflection point in cyber warfare: the industrialization of AI-assisted attack chain development, where threat actors use large language models not just for administrative tasks, but as core infrastructure for generating convincing pretexts, creating realistic decoys, and accelerating malware development.


## The Threat


GreyVibe's campaign is characterized by surgical targeting and diversified attack vectors. While attribution to a Russian nation-state has not been confirmed with high confidence, multiple indicators strongly suggest state alignment: Cyrillic language in malware control panels, code comments in Russian, and command-and-control (C2) infrastructure configured to Moscow Standard Time (UTC+3).


The threat group operates with sufficient resources to maintain multiple concurrent campaigns across different vectors—from Android spyware distribution to elaborate fake government websites—while displaying operational characteristics that researchers believe may indicate the involvement of current or former cybercriminals. This hybrid composition suggests a possible evolution in how state actors organize offensive cyber teams, potentially recruiting contractors or former underground forum members to supplement nation-state capabilities.


WithSecure's investigation identified that GreyVibe has successfully compromised targets across multiple sectors, though the primary focus remains Ukrainian military, government, and critical infrastructure personnel. The persistence and sophistication of the campaign indicates sustained adversary investment in Ukraine-focused operations.


## Attack Chains: Five Distinct Operational Models


GreyVibe deploys five primary attack chains, each tailored to exploit specific victim populations:


### PhantomMail

The group distributes spear-phishing emails containing malicious archives (ZIP/RAR files) hosted on cloud services like Google Drive and 4sync. Lures impersonate legitimate Ukrainian government bodies, emergency services (DSNS), telecommunications operators, and energy sector entities. The decoy documents appear authentic, leveraging AI-generated PDFs and fake system error messages to establish initial access.


### PhantomClick

This chain employs fake CAPTCHA verification pages and "ClickFix" prompts disguised to mimic Zoom login pages and LAPAS (a Ukrainian government service). Victims are tricked into executing self-infecting commands through fraudulent Cloudflare security verification prompts—a technique that exploits legitimate security-conscious behavior to deliver payload execution.


### PrincessClub

A particularly concerning vector that weaponizes social engineering at scale. GreyVibe operates fake Ukrainian adult and dating websites that distribute FallSpy (Android spyware) and Windows malware variants (PhantomRelay/LegionRelay). Operators maintain fake female Telegram personas that initiate conversations with targets; the campaign later evolved to include WebRTC-based voice and video calls to establish rapport and capture audio/video credentials.


### DroneLink

Fake Ukrainian military charity websites themed around FPV drones and unmanned aerial vehicles (UAVs) serve as distribution points. This campaign shares hosting infrastructure with PrincessClub, suggesting operational consolidation and resource efficiency.


### Nebo

Named after a fake Russian military communications login page ("СПО НЕБО"), this vector targets Ukrainian military personnel by spoofing access credentials for Russian military terminal interfaces. The psychological element here is significant: military personnel trained to expect Russian command-and-control infrastructure may lower defenses when presented with authentic-appearing Russian military branding.


## Technical Details: Custom Malware Arsenal


GreyVibe's malware toolkit consists of both custom obfuscators and remote access trojans:


| Malware | Type | Primary Capability | Development Notes |

|---------|------|-------------------|-------------------|

| LegionRelay | Windows RAT | File theft, screenshots, browser credential harvesting, RDP setup | Likely developed with LLM assistance |

| PhantomRelay | Windows RAT | System fingerprinting, dynamic script loading, command execution | PowerShell-based, also observed in cybercrime |

| FallSpy | Android Spyware | Contact/call log exfiltration, location tracking, media collection | Platform-specific intelligence gathering |

| LOOKVALPS / LOOKVALJS | Obfuscators | Code obfuscation and evasion | Generated with probable AI assistance |

| DAYLIGHT / TEASOUP | Obfuscators | Payload obfuscation | Likely AI-assisted development |


All malware components are written in scripting languages (PowerShell, JavaScript) optimized for rapid deployment and minimal detection signatures.


## AI-Powered Operations: A New Frontier in Scale


The distinguishing feature of GreyVibe's campaign is the systematic use of generative AI across the attack lifecycle:


Lure Generation: ChatGPT and Google Gemini were used to generate contextually appropriate phishing content with authentic institutional language. Rather than relying on boilerplate templates, the threat group produced custom, context-aware decoys for each target organization.


Image Creation: Ideogram AI and other image-generation models created realistic visual assets for fake websites and social engineering profiles. Analysis of these images revealed characteristic LLM artifacts—subtle inconsistencies that, while imperceptible to untrained eyes, are detectable through technical forensics.


Code Development: Malware obfuscators (LOOKVALPS, LOOKVALJS, DAYLIGHT, TEASOUP) and the LegionRelay RAT show signs of LLM-assisted development, likely leveraging code generation models to accelerate development cycles and reduce the burden on skilled developers.


This represents a fundamental shift: rather than limiting AI to productivity gains, adversaries are embedding AI into operational infrastructure, accelerating the pace at which new campaigns can be launched and iterated.


## Attribution: Nation-State Aligned, But With Caveats


WithSecure stopped short of attributing GreyVibe to a specific Russian state actor, citing several anomalies:


  • Operational discipline gaps: The group "lacked the level of sophistication and operational discipline typically associated with mature nation-state actors," indicating possible outsourcing or supplemental cybercriminal involvement.
  • Malware reuse in cybercrime: PhantomRelay has been observed in generic cybercriminal campaigns, suggesting either shared tooling or actor overlap.
  • Infrastructure indicators: Evidence of involvement by UAC-0098 (a group with suspected ties to former TrickBot members) in early malware samples suggests possible mercenary relationships or recruitment of former underground actors.

  • The assessment aligns with emerging intelligence suggesting that Russian cyber operations increasingly operate through proxies and contractors rather than purely state-employed teams.


    ## Implications for Organizations


    For Ukrainian organizations: This campaign represents an acute, sustained threat. Attackers are demonstrably targeting government, military, and critical infrastructure personnel with convincing social engineering that exploits organizational context.


    For NATO and allied nations: The success of GreyVibe's approach demonstrates that AI-assisted phishing can circumvent traditional email filtering and user awareness training. The prevalence of Ukraine-focused campaigns also suggests that Russian cyber operations are tightly integrated with military planning, serving intelligence-gathering functions in support of ongoing kinetic operations.


    For the cybersecurity industry: This campaign is a harbinger of what adversary-operated AI looks like at scale. As LLMs become ubiquitous, defenders face an arms race where sophisticated social engineering can be generated faster than human security teams can respond.


    ## Recommendations


    Organizations should implement:

  • Multi-factor authentication (MFA) on all sensitive accounts, particularly for military and government personnel
  • Email authentication protocols (DMARC, SPF, DKIM) to prevent domain spoofing
  • User awareness training focused specifically on AI-generated content, with emphasis on verifying unexpected contact through out-of-band channels
  • Endpoint detection and response (EDR) capable of identifying PowerShell-based malware execution patterns
  • Browser credential isolation and credential management solutions to prevent wholesale theft
  • Network segmentation to limit lateral movement if initial compromise occurs

  • ---


    ## HackWire Analysis


    GreyVibe's campaign represents the arrival of an inflection point in cyber warfare that cybersecurity discourse has long anticipated but rarely seen operationalized at this scale: adversary-controlled AI as offensive infrastructure. This is not merely bad actors using ChatGPT; it is the systematic embedding of generative models into attack chains as force multipliers.


    What makes GreyVibe significant is not technical sophistication (the malware is relatively standard), but operational scaling. By outsourcing lure creation, image generation, and code obfuscation to AI, GreyVibe can operate multiple parallel campaigns across diverse victim profiles without proportionally increasing headcount. A single operator with ChatGPT access can generate context-specific phishing for fifty organizations in a day—a task that previously required dedicated social engineers and extensive reconnaissance.


    The attribution ambiguity—state-aligned but disciplined differently than classical nation-state operations—signals something important: the traditional espionage model is eroding. Rather than maintaining large, compartmentalized cyber armies, state actors are increasingly outsourcing to freelancers, former cybercriminals, and contractors who lack institutional discipline but bring speed and deniability. UAC-0098's involvement (former TrickBot infrastructure) suggests these aren't just recruitment relationships; they're shared platforms where nation-state objectives and cybercriminal profiteering overlap.


    For defenders, the strategic takeaway is uncomfortable: you cannot out-train social engineering that is individually tailored to your organization by AI. Phishing resistance now requires technical controls—hardware-backed authentication, impossible travel detection, behavioral anomaly detection—not awareness alone.


    For policymakers, GreyVibe is a case study in why LLM export controls matter. OpenAI's usage policies do not prevent sophisticated threat actors from using ChatGPT; they only constrain commercial competitors and smaller actors. The same applies to Gemini and Ideogram. Until consequences exist for state actors weaponizing commercial AI, adversary capability will only accelerate.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)