Activity timeline
GreyVibe appears in 3 tracked threats between and ; the busiest month was 2026-05 with 1 report.
ATT&CK techniques observed
- T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 2 of 3 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 2 of 3 tracked threats
- T1102 Web Service — Command and Controlobserved in 2 of 3 tracked threats
- T1113 Screen Capture — Collectionobserved in 2 of 3 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1204 User Execution — Executionobserved in 2 of 3 tracked threats
- T1505 Server Software Component — Persistenceobserved in 2 of 3 tracked threats
- T1555 Credentials from Password Stores — Credential Accessobserved in 2 of 3 tracked threats
- T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 2 of 3 tracked threats
- T1566.002 Spearphishing Link — Initial Accessobserved in 2 of 3 tracked threats
- T1583 Acquire Infrastructure — Resource Developmentobserved in 2 of 3 tracked threats
- T1005 Data from Local System — Collectionobserved in 1 of 3 tracked threats
- T1014 Rootkit — Stealth (formerly Defense Evasion)observed in 1 of 3 tracked threats
Tracked threats
- AI-Enhanced Phishing and Adversary-in-the-Middle (AiTM) Phishing-as-a-Service Ecosystem — 2025-2026 Threat LandscapeHIGH
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain CompromiseMEDIUM
- GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine: LegionRelay/PhantomRelay PowerShell RATs & FallSpy Android Spyware (WithSecure)HIGH