The images in this article were generated with artificial intelligence. How we publish
A new cyber-espionage actor that WithSecure researchers have marked as GreyVibe has shown in recent months a disturbing combination: highly polished lures generated with artificial intelligence tools and a malware toolbox of its own that targets military, government, civil and business objectives with special interest in organizations linked to Ukraine. According to the public analysis of WithSecure ( report by WithSecure), the operative has used from mail lures and false pages to remote access Trojans and mobile spyware, suggesting a multifaceted campaign designed to obtain intelligence and persistent access.
The most relevant from the tactical point of view It is not only that the baits are credible, but that many come from content and assets generated with language and image models: speech-phishing texts, false site interfaces and graphics that mimic official portals. This automation allows for the production of scale and realism that is difficult to detect without technical controls and adequate training. In addition, researchers identified malware as LegionRelay and PhantomRelay (PowerShell RATs) and FallSpy on Android, along with obfuscation tools with names like LOOKVALJS and DAYLIGHT, which probably incorporated IA assistance in their development.

Political attribution appears as a grey stripe. There are linguistic and tactical signs that point to Russian speakers and to time-bound UTC + 3, and the campaigns are aligned with what would be state interests towards Ukrainian objectives. However, WithSecure highlights atypical behaviour for a mature state actor: exposure of development samples on public platforms, occasional use of a cryptomoneda mining plant in compromised systems and reuse of components associated with criminal groups. All this suggests a possible hybrid between criminal actors and State-related elements, or criminal operations that receive or follow external guidance.
The modalities of attack observed range from speed-phishing with ZIP / RAR files hosted in cloud services, false verification pages that induce self-executable commands (imitating CAPTCHAs or Cloudflare verifications), fraudulent dating sites or adult content that install mobile spyware and charity pages or drone-themed infections to capture military or voluntary personnel. Bits focused on communication applications (e.g. Zoom simulations or false military portals) seek both credentials and remote code execution and messaging exfiltration from Telegram and WhatsApp.
Implications for organizations and individuals: The combination of realistic lures and modular malware increases the risk of intrusion and sensitive intelligence theft, and the presence of audio and video capture capabilities via WebRTC increases the consequences to loss of privacy and exposure of real-time operations. The fact that part of the development appears in public spaces also makes it easier for defenders to identify technical indicators, but does not reduce the operational danger for equipment that does not have specific controls against these techniques.

To mitigate this threat, there is a mix of technical and operational measures that should be implemented with priority. From a technical point of view, it is essential to apply filtering and mail inspection that detects links to public clouds and incoming compressed files, force robust multifactor authentication and perform critical applications to avoid arbitrary execution of unapproved PowerShell or binary. Security teams should integrate publicly available IoC and detection rules - for example the list of indicators accompanying the WithSecure analysis ( IoCs in GitHub) - and adjust EDR detections for specific search of chains and behaviors associated with LegionRelay, PhantomRelay and FallSpy mobile spyware.
At the human and procedural levels, it is essential to train staff to recognize sophisticated lures: false pages of verification, requests of clicks involving execution of commands and false profiles on social networks seeking conversations to induce confidence. Technical areas should coordinate clear rules on the use of personal devices and clearly separate sensitive access in environments with minimum risk of exposure. It is also appropriate to review file ingestion policies from cloud services and to audit any legitimate use that can be used as a delivery vector.
Finally, the hybrid nature of the actor forces to maintain a proactive threat hunting position: to prioritize monitoring of outgoing communications to suspicious domains, to track unusual artifacts in teams that handle sensitive information, and to work with intelligence exchange communities to update rules and blockages. For broader contexts of awareness-raising and good practices in defence of such operations, reference material on detection and response to espionage and spyware campaigns can be consulted on official portals such as the United Kingdom NCSC ( How to identify suspicious emails), in addition to the technical analysis of WithSecure itself.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...