GREYVIBE is a previously undocumented Russia-linked cyber-espionage threat actor active since at least August 2025 and primarily focused on Ukraine and Ukraine-related entities. Available reporting indicates the group is Russian-speaking, operates broadly in the Moscow time zone, and conducts operations aligned with Russian state intelligence interests in the context of the Russia-Ukraine war. At the same time, the actor shows multiple signs of overlap with the broader cybercrime ecosystem, suggesting a hybrid profile rather than a mature, traditional state operator. GREYVIBE has targeted military, government, civilian, and business organizations, with confirmed victimology including Ukrainian combatants. Its intrusion vectors include spear-phishing, ClickFix-style fake verification or CAPTCHA pages, fraudulent adult-themed lure sites, charity-themed lure sites, and Telegram-based social engineering using fabricated personas. Campaigns associated with the actor include PhantomMail, PhantomClick, PrincessClub, DroneLink, and Nebo. The group deploys custom malware and supporting tooling including PhantomRelay, LegionRelay, and FallSpy, along with custom obfuscators and loaders such as LOOKVALPS, LOOKVALJS, DAYLIGHT, and TEASOUP. PhantomRelay is a PowerShell-based remote access trojan used for command execution and post-compromise control. LegionRelay is a lightweight PowerShell-based RAT used for file enumeration, file theft, screenshot capture, browser data theft, messaging-app data theft, and enabling remote desktop access. FallSpy is an Android spyware implant used to collect device, communications, location, and media data from infected mobile devices. Later PrincessClub infrastructure also incorporated WebRTC-based audio and video capture, indicating an expansion from malware delivery into direct surveillance and possible HUMINT-supporting collection. A defining characteristic of GREYVIBE is systematic use of generative AI and large language models across much of the attack lifecycle. The actor has been linked to use of ChatGPT, Google Gemini, and Ideogram AI for lure creation, image generation, malware and obfuscator development, infrastructure setup, and post-compromise command generation. This AI-assisted workflow appears to have helped the group scale campaigns, localize social-engineering content, rotate code structures, and compensate for capability gaps. Despite sustained activity and broad AI integration, GREYVIBE is generally assessed as low to moderately sophisticated. The actor has made repeated operational security mistakes, including exposing backend functionality through design flaws in LegionRelay and leaving immature development artifacts. Reporting also notes indicators of cybercrime adjacency, including tooling overlaps with criminal ecosystems and limited deployment of cryptocurrency mining payloads on some compromised systems. No definitive linkage to a previously tracked threat group is established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted Ukraine-related organizations while incorporating generative AI and LLMs into operations.
Russia-linked cyber espionage group using AI tools to help build malware, spin up infrastructure, and craft lures for attacks on Ukrainian targets.
Cyber espionage operations targeting Ukrainian entities and Eastern Europe using multi-vector social engineering, phishing, fake verification pages, romance lures, and custom implants for intelligence collection.
Conducting AI-assisted attack campaigns against Ukrainian military, government, civilian, and business organizations using custom obfuscators, fake content, loaders, and malware across multiple parallel attack chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.