GreyVibe

First seen
2022-02-01 00:00:00
Origin
RU
Primary motivation
espionage
Sophistication
intermediate
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:29:41

Targeted industries: government-and-public-sector defense-and-aerospace energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:ua

Context

GREYVIBE is a low-to-moderately sophisticated threat actor associated with Russian state interests, primarily targeting Ukrainian entities. The group employs custom malware like LegionRelay and PhantomRelay, utilizing techniques such as decoy-and-payload execution logic and systematic use of GenAI and LLMs throughout their operations. Their campaigns exhibit operational overlaps with other groups, including shared C2 infrastructure and post-compromise tooling. WithSecure has identified design flaws in their malware that have provided insights into their victimology and operational behavior.

Reports & references

  • labs.withsecure.com — Greyvibe (report)

External references