Also known as: tracked as, PrincessClub, PhantomRelayV1, LegionRelay on Windows, Google's Gemini
GREYVIBE is a low-to-moderately sophisticated threat actor associated with Russian state interests, primarily targeting Ukrainian entities. The group employs custom malware like LegionRelay and PhantomRelay, utilizing techniques such as decoy-and-payload execution logic and systematic use of GenAI and LLMs throughout their operations. Their campaigns exhibit operational overlaps with other groups, including shared C2 infrastructure and post-compromise tooling. WithSecure has identified design flaws in their malware that have provided insights into their victimology and operational behavior.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GreyVibe is a threat actor of moderate sophistication linked to Russian state interests, primarily targeting Ukrainian entities. The group employs custom malware and leverages advanced techniques including GenAI and LLMs, posing a persistent cyber threat to critical infrastructure in Ukraine.
Goals & Targeting
GreyVibe's strategic objectives appear to align with broader Russian interests in destabilizing Ukrainian entities, likely seeking to achieve political or disruptive outcomes. The group's focus on Ukraine suggests a nation-state backed operation aimed at undermining Ukrainian sovereignty or critical infrastructure through cyber-physical attacks. Their targeting of sectors critical to Ukraine's economy and national security indicates an intent to destabilize the country.
Enhanced Description
GreyVibe operates with moderate sophistication, demonstrating a focus on tailored attacks against Ukrainian targets. Their arsenal includes custom malware such as LegionRelay and PhantomRelay, which utilize decoy-and-payload execution logic. The group's operations indicate a systematic approach to integrating GenAI and LLMs into their attack workflows. GreyVibe's activities overlap with other groups, sharing C2 infrastructure and post-compromise tooling, suggesting potential collaboration or shared origins. Despite these overlaps, WithSecure has identified design flaws in GreyVibe's malware that provide critical insights into their targeting behavior and victimology.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
GreyVibe's campaigns exhibit operational overlaps with other threat groups, including shared C2 infrastructure and tooling. Their targeting patterns suggest a focus on Ukraine's critical sectors, and their use of sophisticated techniques indicates an evolving threat. WithSecure's analysis highlights design flaws in GreyVibe's malware that have been exploited to gain insights into their attack patterns.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is moderate. While WithSecure has identified overlaps with other groups and provided detailed analysis of GreyVibe's malware, there are gaps in understanding their exact modus operandi, campaign timelines, and specific aliases. Further intelligence sharing and analysis would enhance clarity.
No campaigns linked yet.
No observed data linked yet.
6
Techniques
42
Tools
0
Campaigns
2
IOCs
0
Observed Data
3
Tactics