GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine: LegionRelay/PhantomRelay PowerShell RATs & FallSpy Android Spyware (WithSecure)

GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine (TL-2026-0622), also tracked as GreyVibe, is a high-severity malware campaign, first published 2026-05-28. It is attributed to GreyVibe (Russia) with medium confidence, affects Microsoft Windows (endpoints), maps to 27 MITRE ATT&CK techniques (T1021, T1027, T1036), and is covered by 9 detection rules and 34 indicators of compromise.

Key facts for TL-2026-0622

Threat ID
TL-2026-0622
Also known as
GreyVibe, PhantomMail, PhantomClick, PrincessClub, DroneLink, Nebo
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-05-28
Last reviewed
2026-05-28
Attribution
GreyVibe
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
military, government, defense, energy, telecommunications, emergency-services, civilian, business
Target regions
Ukraine, Eastern Europe
Detection rules
9
Indicators of compromise
34

Malware and tooling in GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine

Malware and tooling: FallSpy, LegionRelay, PhantomRelay, DAYLIGHT, LOOKVALJS, LOOKVALPS

GreyVibe is a likely Russian-aligned threat cluster targeting Ukrainian and Ukraine-related military, government, civilian, and business entities since at least August 2025 (disclosed by WithSecure in January 2026). The actor makes extensive use of generative-AI tools (ChatGPT, Google Gemini, Ideogram AI) to mass-produce convincing phishing lures and to assist development of custom obfuscators and malware, deploying the LegionRelay and PhantomRelay PowerShell RATs on Windows and the FallSpy spyware on Android across five named campaigns.

How GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine works

GreyVibe is a threat cluster, tracked by WithSecure and disclosed publicly in 2026, that conducts espionage-oriented operations against Ukrainian and Ukraine-related organizations across the military, government, civilian, and business sectors. Activity dates to at least August 2025 and continued into 2026. Attribution to a Russian-speaking, likely Russian-aligned operator rests on the language used in the malware control panels, comments in code artifacts, and command-and-control (C2) server clocks configured to UTC+3 (Moscow time). WithSecure assesses the group lacks the operational discipline of a mature nation-state service — notably uploading development and test samples to public scanning platforms — and likely blends state-aligned tasking with current or former cybercriminal operators. A unique ISO builder links early/test samples to former TrickBot members (UAC-0098), who targeted Ukraine at the outset of the full-scale invasion.

A defining trait of GreyVibe is the operational use of generative AI. WithSecure attributes the volume, diversity, and polish of the actor's lures to ChatGPT, Google Gemini, and Ideogram AI, which were used to generate realistic decoy documents, imagery, and social-engineering content, and to assist in writing malware and the group's custom obfuscators. The custom tooling family includes the LOOKVALPS (PowerShell) and LOOKVALJS / TEASOUPJS (JavaScript) loaders and the DAYLIGHT script obfuscator — code WithSecure assesses was likely produced with LLM assistance.

The intrusion set is organized into five campaigns. PhantomMail uses spear-phishing emails that deliver malicious ZIP/RAR archives via Google Drive and 4sync links, opening decoy PDFs or fake error messages while staging loaders; observed lures impersonated Ukrainian government, emergency (DSNS), telecom, and energy (Centrenergo) entities, with Ukrainian-language filenames such as 'форма акта перевірки.XLS.js'. PhantomClick employs fake CAPTCHA/ClickFix pages disguised as Zoom (zoomconference.app/.click) and LAPAS (lapas.live) sites, using bogus Cloudflare verification prompts to trick victims into pasting and running self-infecting commands. PrincessClub stands up fake Ukrainian adult/dating websites that deliver FallSpy Android spyware and PhantomRelay/LegionRelay Windows malware, operated with fake female Telegram personas (e.g. vikagogogo111) and WebRTC-based live video calls that capture victim audio/video. DroneLink uses fake Ukrainian military charity sites themed around FPV drones and UAVs (frontforce.org, ukrguard.org), sharing infrastructure and tooling with PrincessClub. Nebo presents fake Russian military communications (СПО НЕБО) login pages to convince Ukrainian military personnel they are accessing a Russian military terminal.

LegionRelay is a PowerShell RAT supporting file theft, screenshot capture, browser credential theft, Telegram and WhatsApp data exfiltration, and RDP access setup. It persists via scheduled tasks masquerading as legitimate software ('Adobe working', 'AMD Checker', 'BackUp checker') and drops its client to paths such as C:\ProgramData\AMD\amd.ps1. It uses a Telegram dead-drop resolver (t.me/s/sdgsersergser) and HTTP C2 over port 8000 (e.g. 194.87.128.243:8000).

PhantomRelay is a second PowerShell RAT supporting system fingerprinting, dynamic script loading, and arbitrary PowerShell/Windows command execution. Observed in V1, V2, and a 'Lite' variant, it persists via watchdog scripts (SysCheckupService.ps1, RzUpdateManager.ps1) and scheduled tasks impersonating system/Razer services, staging under %ProgramData%\WindowSystem and %LOCALAPPDATA%\Razer Update. PhantomRelayLite has also been seen in broader cybercrime activity, including Teams vishing and KongTuke-style delivery, indicating tool overlap between espionage and criminal use. RAT client and watchdog scripts are frequently obfuscated with DAYLIGHT.

FallSpy is Android spyware used in the PrincessClub and Nebo campaigns purely for intelligence collection: it harvests contact lists, call logs, device and network information, location data, media files, and SIM information. It is delivered as themed APKs (dating, mapping, 'Elite Dance Studio', cloud-storage, and fake NEBO military-terminal apps). A cryptocurrency miner was additionally deployed on some compromised Windows machines, indicating opportunistic monetization alongside espionage. Collectively GreyVibe presents a cross-platform (Windows + Android), AI-accelerated threat to Ukrainian defense and government targets, with a large, well-documented IOC footprint published by WithSecure.

MITRE ATT&CK techniques used in TL-2026-0622

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1219 Remote Access Tools

Discovery

T1082 System Information Discovery

Collection

T1113 Screen Capture; T1119 Automated Collection; T1123 Audio Capture; T1125 Video Capture; T1430 Location Tracking; T1533 Data from Local System; T1636 Protected User Data

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

Impact

T1496 Resource Hijacking

Credential Access

T1555 Credentials from Password Stores

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

Affected products and versions in GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine

  • Microsoft — Windows (endpoints)
    Vulnerable versions: all supported
  • Google — Android
    Vulnerable versions: all (sideloaded APK)
  • Multiple — Web browsers (credential stores)
    Vulnerable versions: Chromium-based; Firefox
  • Telegram — Telegram Desktop
    Vulnerable versions: all
  • Meta — WhatsApp
    Vulnerable versions: desktop

Remediation for GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine

Immediate actions

  • Block all WithSecure-published GreyVibe C2 domains and IP:port pairs (e.g. 194.87.128.243:8000, 193.233.23.81, goodhillsenterprise.com) at the perimeter/proxy.
  • Hunt for malicious scheduled tasks named 'AMD Checker', 'BackUp checker', 'Adobe working', 'System Health Service', and 'Razer Synapse Service Helper'.
  • Search endpoints for PowerShell artifacts under C:\ProgramData\AMD, C:\ProgramData\BackUp, %ProgramData%\WindowSystem, and %LOCALAPPDATA%\Razer Update.
  • Quarantine known-bad APKs by hash on managed Android devices and revoke FallSpy-granted permissions.
  • Block Telegram dead-drop resolver access to t.me/s/sdgsersergser and alert on outbound traffic to TCP/8000 toward unfamiliar hosts.

Workarounds

  • Disable execution of PowerShell and Windows Script Host for standard users via AppLocker/WDAC where feasible.
  • Block ZIP/RAR/HTA/JS/PyInstaller-EXE delivery from webmail and cloud-share links (Google Drive, 4sync) at the mail gateway.

Longer-term hardening

  • Enable PowerShell Script Block Logging, Module Logging, and AMSI; alert on obfuscated/encoded PowerShell and dynamic IEX/script loading.
  • Deploy EDR with behavioral detection for ClickFix/FakeCaptcha clipboard-execution chains (mshta/powershell spawned from browser).
  • Enforce mobile MDM with app-allowlisting and sideloading prevention to block FallSpy APK installation.
  • Restrict and monitor RDP; require MFA and network segmentation for administrative access.
  • Run security-awareness training focused on AI-generated lures, fake Cloudflare/CAPTCHA pages, and Ukrainian-government impersonation.

Timeline of GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine

  • GreyVibe activity begins; earliest observed PhantomMail PyInstaller loaders and ZIP archives (e.g. K-Lite-icon loader) target Ukrainian entities.
  • PhantomMail continues with new ZIP archives and LOOKVALJS JavaScript loaders.
  • PhantomMail spear-phishing impersonates Centrenergo (energy sector) using Gmail sender addresses; RAR archives and LOOKVALJS loaders observed.
  • WithSecure discovers and begins tracking the GreyVibe cluster, attributing activity to a likely Russian-aligned, Russian-speaking operator.
  • PhantomMail impersonates Ukraine's State Emergency Service (DSNS); TEASOUPJS JavaScript loaders introduced.
  • PhantomMail impersonates Ukrainian government civil-protection offices (CIP); further RAR and TEASOUPJS samples observed.
  • Public disclosure via BleepingComputer and release of WithSecure GreyVibe IOC set documenting five campaigns, LegionRelay/PhantomRelay/FallSpy malware, and AI-assisted tooling.
  • As of 2026-05-29, GreyVibe is fully active: WithSecure publicly disclosed the Russia-aligned, AI-assisted espionage cluster on 2026-05-28 with observed activity through March-April 2026 and states it "continues to monitor" the group. No takedown, arrest, sinkhole, or disruption reported; five campaigns and LegionRelay/PhantomRelay/FallSpy tooling remain operational against Ukraine.

Sources cited for GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine

Threats related to GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine

Detection coverage for TL-2026-0622

As of 2026-05-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0622 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats