INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Russia-nexus threat group uses AI to target Ukraine and Europe

| 2026-06-15 05:46 MEDIUM LOW AI-ENABLED ATTACK STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A previously undocumented Russia-nexus threat group, tracked as GREYVIBE, has been using AI to target military personnel, government bodies, and businesses across Ukraine since at least August 2025. The group's activities align with Russian state intelligence-gathering objectives in the context of the ongoing Russia-Ukraine war. WithSecure identified indicators placing the group at the intersection of state-aligned activity and the broader cybercrime ecosystem. GREYVIBE uses generative AI, large language models, and multiple AI platforms to produce lure sites, develop custom malware, build obfuscation frameworks, and generate post-compromise scripts, demonstrating deliberate integration into its operational workflow. The current status is that WithSecure has provided rare, sustained visibility into the group's targeting and behaviour due to design flaws in LLM-assisted malware, allowing for monitoring of GREYVIBE's activity across victim machines for several months.
Technical Mitigations AI-generated
• Block or hunt for fake female personas used in social engineering via Telegram. • Use LLM-assisted malware detection techniques to identify custom malware suite, including PhantomRelay and FallSpy. • Monitor systems for signs of LLM-generated post-compromise scripts and use design flaw analysis to detect potential GREYVIBE activity.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
la•••••.com
wi•••••.fi
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
TrickBotTrickBot
Target & Sectors
EUROPE EUROPE defensedefense
Incident Timeline
‎August 2025
Threat actors linked to the Russian-speaking Moscow time zone used AI-assisted custom malware, including a PowerShell-based RAT and Android spyware, to target Ukraine and Europe.
infrastructure Android
Tactical Metrics
Metrics
infrastructure
‎Android
Affected Product