WithSecure
Coverage of WithSecure in the Nexus archive.
- Russia-linked threat group put ChatGPT to work from lure to payload
A Russia-linked cyber espionage group called GREYVIBE has been using AI tools like ChatGPT, Google's Gemini, and Ideogram AI to develop malware, craft phishing lures, and build infrastructure targeting Ukrainian military, government, and civilian organizations. The group's AI integration spans multiple operational phases, though it has made operational security mistakes such as uploading malware to public services and leaving behind identifiable code artifacts.
- New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks
A previously undocumented threat actor, GREYVIBE, has been targeting Ukraine and Ukraine-related entities with AI-powered cyberattacks since at least August 2025. WithSecure attributes GREYVIBE to a Russian-speaking group operating in the Russian time zone, aligning with Kremlin state interests.