# Russian-Linked GREYVIBE Campaign Targets Ukraine with AI-Powered Malware Arsenal


A previously undocumented Russian threat actor known as GREYVIBE has been orchestrating a sustained campaign against Ukraine since at least August 2025, leveraging artificial intelligence to accelerate malware development and scale attacks across military, government, and civilian targets. WithSecure researchers have documented the group's sophisticated yet operationally flawed approach, revealing how state-affiliated cyber operations are increasingly augmenting traditional espionage tactics with generative AI tools.


## The Threat: GREYVIBE's Scope and Scale


GREYVIBE operates as a Russian-speaking group aligned with Kremlin state interests, conducting intelligence-gathering operations that underscore Russia's ongoing information warfare campaign against Ukraine. The threat actor has demonstrated persistence and adaptability, cycling through multiple attack vectors to reach diverse victim categories—from military and government officials to private sector businesses and NGOs.


What distinguishes GREYVIBE from conventional threat actors is its hybrid nature: while assessed to be a state-sponsored group, it maintains operational ties to the broader Russian cybercrime ecosystem, with evidence suggesting current or former cybercriminal members participate in the operations. This combination of state resources and underground expertise has enabled the group to maintain operational tempo despite numerous security blunders.


Victim Profile:

  • Military and defense organizations
  • Government ministries and agencies
  • Civilian and business entities
  • Non-governmental organizations (NGOs)
  • Infrastructure operators

  • ## Technical Details: Six Attack Chains


    WithSecure identified six distinct attack chains, each employing different social engineering tactics, delivery mechanisms, and post-compromise payloads:


    ### PhantomMail: Phishing-Based Delivery

    The group uses targeted spear-phishing emails to distribute links pointing to malicious archives (ZIP and RAR files) hosted on legitimate cloud services including Google Drive and 4sync. These archives contain JavaScript-based loaders designed to execute decoy documents while silently launching malware payloads. This approach exploits user trust in legitimate cloud platforms and the plausibility of file-sharing scenarios common in professional environments.


    ### PhantomClick: Fake CAPTCHA Social Engineering

    Employing ClickFix-style tactics, GREYVIBE operators create bogus websites impersonating Zoom and LAPAS (a Ukrainian software provider) with fake CAPTCHA verification pages. Victims are social engineered into running commands that trigger the PhantomRelay infection chain. This technique leverages users' familiarity with CAPTCHA challenges and their expectation of legitimate security verification.


    ### PrincessClub: Adult Club Lure Sites

    One of the more insidious vectors, PrincessClub deploys fake Ukrainian adult club websites to deliver platform-specific malware. Windows users receive PhantomRelayV1 or LegionRelay, while Android devices are compromised with FallSpy. Later iterations of these lure sites introduced WebRTC-based live video features to capture victim audio and video in real time—suggesting the sites may serve dual purposes: infection and intelligence gathering.


    ### DroneLink: Charity Front Organizations

    GREYVIBE created websites impersonating charitable foundations supporting Ukraine's Armed Forces to distribute WireGuard VPN clients and LegionRelay. This vector exploits the legitimacy of military support organizations and the perceived need for secure communications among defenders.


    ### Nebo: Military Credential Harvesting

    The Nebo campaign uses fake Russian-language login screens, likely targeting Ukrainian military personnel with the implication that they are accessing Russian military systems. This psychological manipulation, combined with the use of FallSpy for credential theft, represents a particularly sophisticated social engineering approach.


    ### Malware Arsenal Summary


    | Tool | Type | Capabilities |

    |------|------|--------------|

    | PhantomRelay | PowerShell RAT | Host profiling, script execution, Windows command execution |

    | PhantomRelayV1 | PowerShell RAT Variant | Adds custom watchdog persistence mechanism |

    | LegionRelay | Lightweight RAT | File enumeration, exfiltration, screenshots, browser data theft, messaging app data theft, RDP setup |

    | FallSpy | Android Spyware | Data harvesting from mobile devices |

    | WireGuard | VPN/Tunneling | Command and control tunnel establishment |


    ## The AI Advantage: How Generative AI Accelerates Operations


    GREYVIBE's incorporation of generative AI platforms represents a significant evolution in threat actor capabilities. WithSecure researchers documented the group's use of:


  • Ideogram AI – for generating convincing lure images and website graphics
  • OpenAI ChatGPT – for developing malware code, obfuscation techniques, and operational documentation
  • Google Gemini – for code generation and refactoring tasks

  • ### Operational Impact of AI Integration


    The adoption of GenAI tooling provides GREYVIBE with several strategic advantages:


    1. Skill Gap Bridging – Team members lacking advanced development expertise can generate functional code with AI assistance, democratizing malware development

    2. Accelerated Iteration Cycles – New variants, obfuscators, and loaders can be generated and deployed faster than traditional manual development

    3. Operational Obscurity – Frequently regenerated tools complicate attribution and detection by reducing reliance on signature-based indicators from previously known malware

    4. Resource Efficiency – Smaller teams can maintain higher output through AI-assisted development


    ## Background and Context: Ukraine as a Persistent Battleground


    Ukraine remains one of the most targeted nations for cyber espionage globally, facing campaigns from multiple Russian APT groups including Gamaredon, Turla, and Wizard Spider. GREYVIBE's emergence and sustained operations reflect Russia's strategic imperative to gather intelligence on Ukrainian military capabilities, political decision-making, and civilian infrastructure.


    The August 2025 operational start date coincides with an intensification of hybrid warfare tactics, following increased drone and missile attacks. Intelligence gathered through GREYVIBE's compromises likely supports targeting decisions and strategic planning at higher organizational levels.


    GREYVIBE's operational security failures—including exposure of infrastructure, reuse of identified tools, and time-zone pattern analysis—suggest the group may prioritize speed and volume over careful tradecraft, consistent with organizations operating under escalating pressure to produce intelligence.


    ## Implications for Organizations and Defenders


    Organizations with Ukraine exposure or Ukrainian personnel face elevated risk from this campaign. Targets extend beyond military and government to include:


  • Businesses with Ukrainian operations or supply chain dependencies
  • International NGOs operating in Ukraine
  • Media organizations covering the conflict
  • Software companies serving Ukrainian markets
  • Diaspora communities and organizations supporting Ukraine

  • The group's effectiveness stems not from sophisticated zero-days or advanced techniques, but from convincing social engineering, persistence, and willingness to adapt delivery mechanisms rapidly. Defenders cannot rely on specialized threat intelligence alone—foundational security hygiene remains critical.


    ## Recommendations for Defense and Incident Response


    Immediate Actions:

  • Email security: Implement DMARC, SPF, and DKIM authentication; block archive attachments in email; use URL sandboxing for cloud links
  • Endpoint hardening: Disable JavaScript execution from downloaded files; enable Windows Defender Exploit Guard; monitor PowerShell execution
  • Application whitelisting: Restrict PowerShell and script execution to approved scripts only
  • Mobile security: Deploy Mobile Device Management (MDM) with app vetting; monitor for unauthorized app installation

  • Detection and Monitoring:

  • Hunt for WireGuard artifacts in network logs and process execution
  • Monitor for unusual PowerShell activity from non-administrative users
  • Alert on suspicious WebRTC API usage
  • Track file exfiltration patterns to anomalous IP addresses

  • Organizational Resilience:

  • Conduct security awareness training with emphasis on recent GREYVIBE tactics
  • Implement MFA across all critical systems
  • Maintain offline backup capabilities and test recovery procedures
  • Establish incident response coordination with government CIRT/CERT if applicable

  • ---


    ## HackWire Analysis


    GREYVIBE's campaign highlights a critical inflection point in cyber conflict: state-sponsored actors are now competing on development velocity and tool diversity rather than technical sophistication alone. By adopting generative AI for rapid malware iteration, GREYVIBE exemplifies how contemporary threat actors are solving a persistent problem—attribution through tool reuse—with commodity AI platforms.


    What's particularly notable is the group's operational immaturity working *in tandem* with AI assistance. These are not elite APT programmers; they're pragmatists generating functional malware at scale. This democratization of malware development should concern every security organization: the barrier to entry for producing deployable tools has collapsed when a team member with no reverse engineering background can prompt ChatGPT for obfuscation routines.


    The timing also matters. GREYVIBE's emergence and rapid evolution suggest Russian cyber operations may be experimenting with AI-augmented tradecraft before consolidating these approaches across their broader APT portfolio. If successful, expect to see similar patterns in operations targeting NATO allies and Western critical infrastructure.


    For defenders, the silver lining: GREYVIBE's reliance on social engineering and commodity cloud platforms means detection is achievable without advanced threat hunting. Organizations that block JavaScript from downloaded files, enforce email authentication, and teach employees to distrust out-of-context requests will deflect most attacks. The gap isn't in technology—it's in execution discipline.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Cyber Espionage](https://www.hackwire.news/category/cyber-espionage) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)