GREYVIBE Uses ChatGPT, Gemini to Build Malware in Ukraine Campaign Since August 2025
Researchers have identified GREYVIBE as a previously unknown threat actor that has targeted Ukraine's military, government, civilian and business sectors since at least August 2025, using spear-phishing, fake CAPTCHA pages and fraudulent websites to deliver custom malware. New details indicate the group used AI tools including ChatGPT and Google Gemini to build and obfuscate malware more quickly, and image-generation tools to help craft phishing emails and fake Ukrainian websites.
The campaign has remained active for nearly a year and appears tied to cybercrime networks, according to researchers, who said the attackers also made security mistakes that exposed parts of their infrastructure. In one technique, the group used a stolen meeting schedule to create a fake Webex page and used JSONPing to confirm infection before deploying follow-on payloads; researchers also reported increasing use of DWAgent for post-exploitation and newer backdoors such as HttpMalice.
From the sources (5 posts)
@thehackersnews⚠️ A previously unknown threat actor has been quietly targeting #Ukraine since at least August 2025. GREYVIBE uses spear-phishing, fake CAPTCHA pages, and fraudulent websites to deliver custom #malware to military, government, civilian, an
@thehackersnewsWhat stands out is how they stole a real meeting schedule to create a believable fake Webex page. They also added JSONPing to confirm infection before delivering the next payload. The group is increasing use of DWAgent for post-exploitatio
@tweetthreatnewsGREYVIBE, a new Russian-linked threat actor, has targeted Ukraine since August 2025 using phishing, fake CAPTCHA pages, and AI-assisted malware to deliver persistent cyberattacks. #Ukraine #GREYVIBE #PhantomRelay
@thehackersnewsNew details show GREYVIBE is using AI tools like #ChatGPT and #Gemini to build and hide its custom malware faster. The group has stayed active for nearly a year, focusing mainly on #Ukrainian targets. Security researchers believe it has ti
@cybernewsliveA Russia-linked hacking crew called GREYVIBE has been running AI-assisted espionage attacks against Ukrainian military, government, and civilian targets since at least August 2025. The group used ChatGPT, Google Gemini, and image-generation