GreyVibe
- First seen
- 2022-02-01 00:00:00
- Origin
- RU
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:29:41
Targeted industries: government-and-public-sector defense-and-aerospace energy-and-utilities technology-and-telecommunications
Targeted regions: country_code:ua
Context
GREYVIBE is a low-to-moderately sophisticated threat actor associated with Russian state interests, primarily targeting Ukrainian entities. The group employs custom malware like LegionRelay and PhantomRelay, utilizing techniques such as decoy-and-payload execution logic and systematic use of GenAI and LLMs throughout their operations. Their campaigns exhibit operational overlaps with other groups, including shared C2 infrastructure and post-compromise tooling. WithSecure has identified design flaws in their malware that have provided insights into their victimology and operational behavior.
Reports & references
- labs.withsecure.com — Greyvibe (report)