Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Man Who Understood Risk: Robert N. Charette retires.

    August 1, 2026

    7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

    August 1, 2026

    Gemini Robotics 2 Brings Google’s AI Into the Physical World

    August 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Man Who Understood Risk: Robert N. Charette retires.
    • 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
    • Gemini Robotics 2 Brings Google’s AI Into the Physical World
    • This AI Assistant Wants to Make Up for Your Boyfriend’s Incompetence
    • Europe Approves Bionic Eye to Restore Vision Lost to Blindness
    • Chinese AI Researchers Are Finding Their Voice on X
    • AI Slop Melodramas Are Taking Over X—and Their Creators Are Cashing In
    • Montana’s new “right to try” law can’t come soon enough for some
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
    Cybersecurity

    GreyVibe hackers use ChatGPT, Gemini to power cyberattacks

    kirklandc008@gmail.comBy kirklandc008@gmail.comMay 29, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A likely Russian threat group tracked as GreyVibe has been using AI-generated lures and a rich set of custom malware tools to target entities in the military, government, civilian, and business sectors.

    The cyberespionage campaign has been active since at least August 2025 and appears to align with Russian state interests, although researchers cannot confidently classify it as a nation-state operation.

    Cybersecurity company WithSecure discovered the activity in January this year and determined that its focus is on Ukrainian or Ukraine-related organizations.

    The link to a Russian-speaking threat actor is supported by the language for the malware panels, comments in code artifacts, and command-and-control (C2) server time configured to UTC+3 (Moscow time).

    According to the researchers, GreyVibe has used several attack chains against its targets, including:

    • PhantomMail: Spear-phishing emails delivering malicious ZIP/RAR archives via Google Drive and 4sync links, using decoy PDFs or fake errors while deploying malware. The observed lures impersonated Ukrainian government, emergency, telecom, and energy entities.
    • PhantomClick: Fake CAPTCHA/ClickFix pages disguised as Zoom and LAPAS sites trick victims into running self-infecting commands through fake Cloudflare verification prompts.
    • PrincessClub: Fake Ukrainian adult/dating websites delivering FallSpy Android spyware and PhantomRelay/LegionRelay Windows malware. The operators used fake female Telegram personas and later added WebRTC-based live calls that could capture the victim’s audio/video.
    • DroneLink: Fake Ukrainian military charity websites themed around FPV drones and UAVs shared infrastructure and tooling with PrincessClub campaigns.
    • Nebo: Fake “СПО НЕБО” Russian military communications login pages were likely designed to trick Ukrainian military personnel into believing they were accessing a Russian military terminal.

    The diversity and quality of these lures are notable, and WithSecure says this is the result of using multiple AI tools, including ChatGPT, Ideogram AI, and Google Gemini, to generate detailed and realistic content to support them.

    LLM markers in images used by GreyVibe
    source: WithSecure

    The use of AI extends to the creation of tools as well, with the researchers mentioning LOOKVALPS, LOOKVALJS, DAYLIGHT, and TEASOUP, all custom obfuscators that were likely developed with LLM assistance.

    A PowerShell-based remote access trojan named LegionRelay was also likely developed with assistance from AI tools, the researchers say.

    LegionRelay supports file theft, screenshot capturing, browser credential theft, Telegram and WhatsApp data exfiltration, and RDP access setup.

    Another malware used by GreyVibe is PhantomRelay, also a PowerShell RAT. The malware supports system fingerprinting, dynamic script loading, and PowerShell and Windows command execution.

    Overview of malware and campaign associations
    Source: WithSecure

    Finally, the hackers employed the FallSpy Android spyware on the PrincessClub and Nebo campaigns, which is designed purely for collecting intelligence.

    The malware collects contact lists, call logs, device and network information, location data, media files, and SIM information.

    WithSecure notes that while GreyVibe activity is consistent with a nation-state operation, the threat actor “lacked the level of sophistication and operational discipline typically associated with mature nation-state actors.”

    Furthermore, the PhantomRelay malware has been seen in cybercrime activity, although researchers could distinguish its usage from state-aligned operations. This led the researchers to believe that GreyVibe may include “current or former cybercriminal actors.”

    Some evidence pointing to this theory includes the use in early and test samples of a unique ISO builder associated with a group of former TrickBot members (UAC-0098) that targeted Ukraine at the start of the Russian invasion.

    Furthermore, the threat actor uploaded development and test samples to a public scanning platform, which is not typical with nation-state actors. Additionally, a cryptocurrency miner was deployed on some victim machines.

    The researchers are unsure “whether former or current cybercriminal members have been absorbed into a state-backed group, operate independently but with state-directed tasking, or have formed a hybrid team involving state-affiliated and cybercriminal members.”

    Organizations can set up defenses against GreyVibe’s malicious activity by using the indicators of compromise (IoCs) provided by WithSecure.

    Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.

    This guide covers the 6 surfaces you actually need to validate.

    Download Now

    ChatGPT cyberattacks Gemini GreyVibe hackers Power
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

    August 1, 2026

    Gemini Robotics 2 Brings Google’s AI Into the Physical World

    August 1, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • The Man Who Understood Risk: Robert N. Charette retires.
    • 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
    • Gemini Robotics 2 Brings Google’s AI Into the Physical World
    • This AI Assistant Wants to Make Up for Your Boyfriend’s Incompetence
    • Europe Approves Bionic Eye to Restore Vision Lost to Blindness

    The Man Who Understood Risk: Robert N. Charette retires.

    August 1, 2026

    7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

    August 1, 2026

    Gemini Robotics 2 Brings Google’s AI Into the Physical World

    August 1, 2026

    This AI Assistant Wants to Make Up for Your Boyfriend’s Incompetence

    August 1, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.