A new threat cluster has surfaced in the Russia-Ukraine conflict. It blends custom malware with heavy reliance on public AI tools. Researchers at WithSecure tracked the activity under the name GREYVIBE. Operations began at least in August 2025 and continue today.
The group focuses on Ukrainian military, government, civilian, and business targets. Lures and post-compromise actions point to intelligence collection tied to the ongoing war. Russian-speaking operators appear active in the Moscow time zone. Ties to the broader cybercrime scene complicate clean attribution.
WithSecure published its findings on May 28, 2026. The report details multiple campaigns and a small family of custom tools. AI assistance shows up across lure creation, code development, and command generation. WithSecure Labs report.
GREYVIBE runs several distinct infection chains.
PhantomMail relies on spear-phishing emails. Victims receive links to ZIP or RAR archives hosted on Google Drive or 4sync. The archives contain JavaScript or PyInstaller loaders. These drop a decoy document while launching PhantomRelay in the background. Lures impersonate Ukrainian officials, energy firms, and emergency services.
PhantomClick uses fake CAPTCHA pages styled after Zoom or other legitimate sites. Victims follow prompts that execute commands. The commands pull down PhantomRelay. Decoy redirects help maintain the illusion of a normal verification step.
PrincessClub deploys fake Ukrainian adult-club websites. These deliver FallSpy Android spyware alongside PhantomRelay or LegionRelay on Windows. Operators use Telegram personas to steer targets to the sites. Later versions added WebRTC live-call features that can capture audio and video after infection.
DroneLink overlaps with PrincessClub infrastructure. It uses fake charity sites themed around support for Ukrainian armed forces and drones. Shared tooling includes WireGuard and additional post-compromise scripts.
Nebo artifacts mimic a Russian military communications login screen. The goal appears to be tricking Ukrainian personnel into believing they access a Russian terminal.
PhantomRelay serves as a core PowerShell remote access trojan. It fingerprints the host then executes scripts and commands via WebSockets. Variants include PhantomRelayLite seen in unrelated cybercrime clusters, PhantomRelayV1 with custom persistence, and PhantomRelayV2.
LegionRelay offers a lighter PowerShell RAT. It handles file enumeration, exfiltration, screenshots, browser theft, messaging app data pulls, and RDP setup. Operators stage additional scripts through its C2.
FallSpy targets Android devices. It harvests contacts, call logs, apps, location, media, and SIM details while showing decoy content.
The group rotates custom obfuscators: LOOKVALPS, LOOKVALJS, DAYLIGHT, and TEASOUP. These wrap payloads and complicate static analysis.
Generative AI powers much of the operation.
WithSecure identified clear markers of ChatGPT, Google Gemini, and Ideogram AI use. The tools helped generate realistic images for lures, craft site content, build obfuscators and loaders, develop LegionRelay, configure backend systems, and produce post-compromise commands. BleepingComputer covered the findings the same day. BleepingComputer article.
AI accelerates development and fills skill gaps. It also reduces reuse of known code that could link campaigns. Yet the approach introduced flaws in LegionRelay. Exposed backend details gave researchers extended visibility into operations. SecurityWeek highlighted this dynamic in its coverage. SecurityWeek report.
Indicators point to Russian-speaking developers. Code comments, admin panels, and server time zones align with Moscow. Some members show signs of prior cybercrime involvement. An ISO builder linked to former TrickBot actors appears in early samples. Development artifacts carry slang names. A few infections deployed an XMRig miner. These elements suggest a hybrid profile rather than a polished nation-state unit.
The Hacker News summarized the campaign on May 29. The Hacker News coverage.
GREYVIBE occupies a grey zone between crime and state interests. Attribution stays difficult. Frequent AI-driven changes to tooling and lures erode traditional clustering methods. WithSecure notes the group lacks the discipline of mature state actors yet demonstrates ambition through AI augmentation.
Defenders gain from the published indicators of compromise. WithSecure shared IoCs and YARA rules on GitHub. Monitoring for the listed domains, hashes, and behaviors helps surface related activity early.
Broader context shows Russia-linked actors expanding AI use in Ukraine operations. Ukrainian officials reported similar trends in malware command generation and social engineering earlier in 2026. GREYVIBE illustrates how lower-sophistication groups can scale quickly with accessible tools.
The activity remains active. Expect continued evolution in lure quality and tool variety. CISOs tracking Ukraine-related threats should incorporate the new signatures and watch for AI-generated content patterns in phishing and site lures.


WebProNews is an iEntry Publication