GreyVibe
Coverage of GreyVibe in the Nexus archive.
- Russia-linked threat group put ChatGPT to work from lure to payload
A Russia-linked cyber espionage group called GREYVIBE has been using AI tools like ChatGPT, Google's Gemini, and Ideogram AI to develop malware, craft phishing lures, and build infrastructure targeting Ukrainian military, government, and civilian organizations. The group's AI integration spans multiple operational phases, though it has made operational security mistakes such as uploading malware to public services and leaving behind identifiable code artifacts.
- New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks
A previously undocumented threat actor, GREYVIBE, has been targeting Ukraine and Ukraine-related entities with AI-powered cyberattacks since at least August 2025. WithSecure attributes GREYVIBE to a Russian-speaking group operating in the Russian time zone, aligning with Kremlin state interests.
- GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
A Russian threat group named GreyVibe is using AI tools like ChatGPT and Gemini to generate lures and deploy custom malware against Ukrainian entities.