FallSpy is an Android spyware family first observed in August 2025 and associated with the GREYVIBE threat cluster. It has been used in campaigns targeting Ukraine and Ukraine-related victims, including operations known as PrincessClub and Nebo. GREYVIBE’s activity has been assessed as aligned with Russian state intelligence interests in the context of the Russia-Ukraine war, while also showing ties to the broader cybercrime ecosystem.
FallSpy is designed to harvest sensitive information from compromised Android devices. Reported collection includes contact lists, call logs, installed application inventories, SIM-linked phone numbers, device and network information, Wi-Fi details, last-known location data, public-facing network information, and media files. Its role in observed operations is intelligence collection from mobile devices, particularly against victims reached through socially engineered lure infrastructure.
Observed delivery has relied on fraudulent websites and tailored social engineering. In the PrincessClub campaign, fake Ukrainian adult-club websites delivered FallSpy to Android users, while parallel Windows-targeted payloads were served to desktop victims. Operators also used fake female personas on Telegram and local dating channels to build trust and direct targets to lure sites or deliver malware directly. In the Nebo campaign, a FallSpy sample was crafted to mimic a Russian-language military login interface, apparently to deceive Ukrainian military personnel. Confirmed victimology linked to associated campaigns includes Ukrainian combatants, with broader GREYVIBE targeting spanning military, government, civilian, and business-related entities.
FallSpy forms part of a wider GREYVIBE malware ecosystem that also includes PhantomRelay and LegionRelay. Administrative artifacts associated with FallSpy have been observed in Russian language, consistent with broader indications that GREYVIBE operators and developers are Russian-speaking and operate broadly in the Moscow time zone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FallSpy is an Android spyware first observed in August 2025. It has been observed across several GREYVIBE-associated campaigns, including PrincessClub and Nebo.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The group has leveraged multiple attack vectors, including... fake captcha pages and fraudulent Ukrainian adult club websites, to deliver malware... PrincessClub... fake Ukrainian adult-club websites that deliver Android spyware called FallSpy, or Windows-based RATs depending on the victim’s device.
The malware presents decoy content to the victim while covertly collecting and exfiltrating information from the victim’s device, including contacts, call logs, installed applications, SIM-linked phone numbers, device and network information, Wi-Fi SSID, last-known location, public IP, and media files.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom Android spyware used in the PrincessClub campaign to harvest private information from infected devices, including contacts and call logs.
Android spyware delivered through fake lure websites and used in campaigns targeting Ukrainian victims, including military-themed deception.
An Android spyware used in GREYVIBE campaigns to harvest sensitive data from compromised mobile devices.
An Android spyware used for surveillance and intelligence gathering. It displays decoy content while covertly collecting contacts, call logs, installed apps, SIM-linked numbers, device/network info, Wi-Fi SSID, location, public IP, and media files for exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.