Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GreyVibe

Also known as: tracked as, PrincessClub, PhantomRelayV1, LegionRelay on Windows, Google's Gemini

Description

GREYVIBE is a low-to-moderately sophisticated threat actor associated with Russian state interests, primarily targeting Ukrainian entities. The group employs custom malware like LegionRelay and PhantomRelay, utilizing techniques such as decoy-and-payload execution logic and systematic use of GenAI and LLMs throughout their operations. Their campaigns exhibit operational overlaps with other groups, including shared C2 infrastructure and post-compromise tooling. WithSecure has identified design flaws in their malware that have provided insights into their victimology and operational behavior.

Goals & Targeting

Targeted Sectors

Government
Defense
Pharmaceutical
Media
Energy

Targeted Countries / Regions

RU
UA
PL

AI Analysis

· 1 week ago

Executive Summary

GreyVibe is a threat actor of moderate sophistication linked to Russian state interests, primarily targeting Ukrainian entities. The group employs custom malware and leverages advanced techniques including GenAI and LLMs, posing a persistent cyber threat to critical infrastructure in Ukraine.

Goals & Targeting

GreyVibe's strategic objectives appear to align with broader Russian interests in destabilizing Ukrainian entities, likely seeking to achieve political or disruptive outcomes. The group's focus on Ukraine suggests a nation-state backed operation aimed at undermining Ukrainian sovereignty or critical infrastructure through cyber-physical attacks. Their targeting of sectors critical to Ukraine's economy and national security indicates an intent to destabilize the country.

Enhanced Description

GreyVibe operates with moderate sophistication, demonstrating a focus on tailored attacks against Ukrainian targets. Their arsenal includes custom malware such as LegionRelay and PhantomRelay, which utilize decoy-and-payload execution logic. The group's operations indicate a systematic approach to integrating GenAI and LLMs into their attack workflows. GreyVibe's activities overlap with other groups, sharing C2 infrastructure and post-compromise tooling, suggesting potential collaboration or shared origins. Despite these overlaps, WithSecure has identified design flaws in GreyVibe's malware that provide critical insights into their targeting behavior and victimology.

Key Capabilities

  • Development and deployment of custom malware (LegionRelay, PhantomRelay)
  • Use of GenAI and LLMs in operations
  • Decoy-and-payload execution logic
  • Systematic use of C2 infrastructure

MITRE ATT&CK Tactics

Initial Access
Execution

Software / Tooling

LegionRelay
PhantomRelay

Campaigns & Victims

GreyVibe's campaigns exhibit operational overlaps with other threat groups, including shared C2 infrastructure and tooling. Their targeting patterns suggest a focus on Ukraine's critical sectors, and their use of sophisticated techniques indicates an evolving threat. WithSecure's analysis highlights design flaws in GreyVibe's malware that have been exploited to gain insights into their attack patterns.

IOC Patterns

  • Spear-phishing campaigns with custom payloads
  • Use of GenAI and LLMs for operational purposes
  • C2 infrastructure sharing with other APT groups
  • Deployment of custom malware with decoy functionality

Recommended Actions

  • Enhance network monitoring for signs of compromised devices communicating with known C2 domains.
  • Implement multi-layered email security to detect and block phishing attempts with custom payloads.
  • Conduct regular software maintenance and patching to mitigate potential vulnerabilities exploited by GreyVibe.

Suggested Tags

APT
cyber_espionage
Ukraine_Russia_conflict
energy_sector
IT_Sector
nation-state_backed

Confidence Assessment

The confidence level in the available data is moderate. While WithSecure has identified overlaps with other groups and provided detailed analysis of GreyVibe's malware, there are gaps in understanding their exact modus operandi, campaign timelines, and specific aliases. Further intelligence sharing and analysis would enhance clarity.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.withsecure.com — Cited by web research for: PrincessClub
  2. www.theregister.com — Cited by web research for: Google's Gemini
  3. attack.mitre.org — Cited by web research for: Interception
  4. thehackernews.com — Cited by web research for: CVE-2026-50522

Intel Summary

6

Techniques

42

Tools

0

Campaigns

2

IOCs

0

Observed Data

3

Tactics

Tags

Backdoor / C2
APT
cyber_espionage
Ukraine_Russia_conflict
energy_sector
IT_Sector
nation-state_backed

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.