LegionRelay is a lightweight PowerShell-based remote access trojan used by the GREYVIBE threat cluster in espionage-focused operations targeting Ukraine and Ukraine-related entities since at least 2025. It communicates with command-and-control infrastructure through REST API methods and has been deployed in Windows-focused intrusion chains associated with fraudulent adult-club lures and charity-themed websites. Reported operator activity shows LegionRelay being used for file enumeration and theft, screenshot capture, browser data theft, extraction of Telegram and WhatsApp data, and setup of Remote Desktop access for follow-on operations. The malware has been associated with campaigns affecting military, government, civilian, and business-related targets, including confirmed Ukrainian combatants. LegionRelay has also been notable for implementation flaws that exposed limited backend functionality, contributing to unusually strong visibility into operator behavior. GREYVIBE has been assessed as a Russian-speaking, Russia-aligned threat actor with ties to the broader cybercrime ecosystem, and LegionRelay is one of its custom implants used alongside other tooling such as PhantomRelay and FallSpy.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lastly, WithSecure identified design flaws in LegionRelay, a custom malware associated with GREYVIBE... LegionRelay is a lightweight PowerShell-based RAT that communicates with its command-and-control server through REST API methods.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
A notable and persistent campaign, tracked as PrincessClub, used fake Ukrainian adult-club websites to deliver FallSpy on Android and PhantomRelayV1 or LegionRelay on Windows.
The group has leveraged multiple attack vectors, including spear-phishing e-mails, fake captcha pages and fraudulent Ukrainian adult club websites, to deliver malware to a diverse set of victims.
Initially, the threat actors initiated at least six unique email-based campaigns. These malicious messages deliver dangerous compression archives hosted on popular public storage services. Furthermore, the files contain automated script loaders that deploy localized documents.
WithSecure observed operators using LegionRelay for file enumeration, file exfiltration, screenshot capture, browser data theft, Telegram and WhatsApp data exfiltration, RDP access setup, among other actions.
WithSecure observed operators using LegionRelay for file enumeration, file exfiltration, screenshot capture, browser data theft, Telegram and WhatsApp data exfiltration, RDP access setup, among other actions.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight REST-based backdoor/client used for data theft, screenshot capture, and messaging database enumeration. The report also notes likely LLM-assisted development and obfuscation-related design flaws.
A lightweight remote access trojan delivered alongside WireGuard through fake charity-themed websites; researchers noted design flaws that exposed backend functionality.
A lightweight PowerShell RAT used by GREYVIBE that supports file enumeration and exfiltration, screenshot capture, browser credential/data theft, Telegram and WhatsApp data theft, and RDP access setup.
Malware used by the GREYVIBE threat group in operations targeting Ukrainian entities; design flaws exposed parts of its backend infrastructure. The report suggests it may have been developed with LLM assistance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.