A Russia-linked threat actor targeting Ukrainian entities, known for custom malware and systematic GenAI integration.
Analyst brief
GreyVibe is a low-to-moderately sophisticated threat actor linked to Russian state interests, primarily targeting Ukrainian entities. The group employs custom malware such as LegionRelay and PhantomRelay, utilizes decoy-and-payload execution logic, and systematically integrates GenAI and LLMs into their operations, while sharing some C2 infrastructure and post-compromise tooling with other groups. Defenders should leverage design flaws in their custom malware for intelligence, apply application control to block decoy-based execution, and strengthen network detection rules focused on C2 infrastructure associated with this group.
GreyVibe
unknown
GREYVIBE is a low-to-moderately sophisticated threat actor associated with Russian state interests, primarily targeting Ukrainian entities. The group employs custom malware like LegionRelay and PhantomRelay, utilizing techniques such as decoy-and-payload execution logic and systematic use of GenAI and LLMs throughout their operations. Their campaigns exhibit operational overlaps with other groups, including shared C2 infrastructure and post-compromise tooling. WithSecure has identified design flaws in their malware that have provided insights into their victimology and operational behavior.