Since at least August 2025, an unidentified threat actor known as GREYVIBE has been linked to continuous and persistent attacks on Ukraine and entities associated with the country.
According to WithSecure, GREYVIBE is evaluated as a Russian-speaking organization that operates widely inside the Russian time zone and whose operations are in line with Kremlin state goals, particularly with regard to intelligence collection activities targeted at Ukraine in the context of the continuing Russo-Ukrainian war.
The organization has distributed malware to a wide range of victims by using a variety of attack routes, such as spear-phishing emails, phony captcha pages, and counterfeit Ukrainian sexual club websites. According to an examination by WithSecure researcher Mohammad Kazem Hassan Nejad. The gang has used malware, loaders, and obfuscators that were specially created for each of these campaigns.
The victimology footprint includes civilian, governmental, military, and commercial entities. Despite its nation-state affiliation read more about New Russia-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
