INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Russia-nexus threat group uses AI to target Ukraine and Europe
| 2026-06-15 05:46 AI-ENABLED ATTACK STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A previously undocumented Russia-nexus threat group, tracked as GREYVIBE, has been using AI to target military personnel, government bodies, and businesses across Ukraine since at least August 2025. The group's activities align with Russian state intelligence-gathering objectives in the context of the ongoing Russia-Ukraine war. WithSecure identified indicators placing the group at the intersection of state-aligned activity and the broader cybercrime ecosystem. GREYVIBE uses generative AI, large language models, and multiple AI platforms to produce lure sites, develop custom malware, build obfuscation frameworks, and generate post-compromise scripts, demonstrating deliberate integration into its operational workflow. The current status is that WithSecure has provided rare, sustained visibility into the group's targeting and behaviour due to design flaws in LLM-assisted malware, allowing for monitoring of GREYVIBE's activity across victim machines for several months.
Technical Mitigations AI-generated
• Block or hunt for fake female personas used in social engineering via Telegram.
• Use LLM-assisted malware detection techniques to identify custom malware suite, including PhantomRelay and FallSpy.
• Monitor systems for signs of LLM-generated post-compromise scripts and use design flaw analysis to detect potential GREYVIBE activity.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
la•••••.com
wi•••••.fi
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Tactical Metrics
Intelligence Sources
Tecnonews
N/A
Tecnonews
N/A