Cybertech Europe 2026-IT Industry Official Media Partner

AI helps Russian-speaking GreyVibe scale up five parallel cyber campaigns against Ukrainian targets

GreyVibe uses AI to scale up cyberattacks against Ukrainian targets GreyVibe uses AI to scale up cyberattacks against Ukrainian targets
According to WithSecure, the Russian-speaking cyber group GreyVibe is using AI tools such as ChatGPT, Google Gemini, and Ideogram AI to streamline cyberattacks against Ukrainian organizations.

Looking for a Shorter Overview?

Key Moments

AI industrializes attacks

AI makes the establishment's attack chains more efficient and scalable.

Need for stronger identity defense

Organizations need to strengthen password management and multi-factor authentication.

Rapid campaign customization

AI enables faster creation and adaptation of cyber campaigns to local conditions.

AI is changing the cybersecurity playing field

AI reduces time and resources for advanced cyber operations and requires AI-based defense technology.

A Russian-speaking cyber group called GreyVibe, which researchers say operates in the Moscow time zone, is using generative AI tools such as ChatGPT, Google Gemini, and Ideogram AI to carry out advanced cyberattacks against Ukrainian targets. The discovery shows how commercially available AI platforms are increasingly being used to streamline and scale cybercriminal operations.

In a blog post published on May 28, researchers at WithSecure how the group uses specially developed obfuscators to generate fake content and deliver malicious code against military, government, civilian and commercial organizations in Ukraine.

AI may make social engineering more effective, but the basic goal of attackers remains the same: to steal login credentials and gain unauthorized access to systems and data.

According to the report, GreyVibe uses five main attack chains: PhantomMail, PhantomClick, Princess Club, DroneLink, and Nebo.

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

AI streamlines established attack methods

Shane Barney, Chief Information Security Officer at Keeper Security, believes that the most remarkable thing is not that the attack methods themselves are new.

– What is remarkable about GreyVibe "It's not that the attack chains are completely new. It's that AI is helping threat actors industrialize them," Barney says.

He explains that AI enables attackers to create more convincing phishing campaigns, fake websites, digital identities, and social engineering materials on a scale that would previously have required significantly greater resources.

“The result is attacks that become more personal, more credible and significantly more difficult for users to distinguish from legitimate communications,” Barney continues.

Focus on identity-based defense

Barney warns that AI-assisted phishing attacks and credential theft campaigns are likely to continue to increase in the coming years.

He recommends that organizations strengthen their identity-based defenses through strong password management, phishing-resistant multi-factor authentication, the principle of least privilege, and continuous monitoring of privileged accounts.

“AI can make social engineering more effective, but the fundamental goal of attackers remains the same: to steal login credentials and gain unauthorized access to systems and data,” says Barney.

Faster adaptation and higher resilience

Sergio Villegas, Senior Managing Analyst II at Bishop Fox, notes that AI and large language models enable threat actors to more quickly develop and adapt their campaigns to local and regional conditions.

He believes that automation of time-consuming tasks has already become an important part of many cyber operations and that the creation of customized decoys and documents is no longer uncommon.

“Speed and precision are the big changes. AI makes it possible to create content that is relevant to specific audiences and situations more quickly,” says Villegas.

He also points out that the ability to reuse or quickly build new malicious infrastructure makes cybercriminal groups more resilient to shutdowns and seizures of cloud and SaaS resources.

“Infrastructure takedowns become less effective when attackers can quickly build new environments and continue their operations,” he says.

Lower thresholds for advanced operations

Yagub Rahimov, CEO of Polygraph AI, believes that the most important conclusion from WithSecure's report is not that yet another threat group is using generative AI.

– The really interesting thing is that AI greatly reduces the time, staffing and specialist expertise required to run cyber operations on a large scale, says Rahimov.

He believes that the development is changing the conditions for both attackers and defenders.

“Actors who previously lacked the resources to conduct credible and long-term operations can now do so significantly faster. At the same time, the same technology is available to both defenders and attackers, which changes the playing field for cybersecurity,” he says.

Security teams must meet AI with AI

Ram Varadarajan, CEO of Acalvio, describes AI as a powerful amplifier for cybercriminal actors.

“The integration of AI effectively gives attackers a new superpower. They can create convincing fake content and tailor-made malware at a speed and scale we haven’t seen before,” says Varadarajan.

He urges organizations to invest more in employee training while complementing traditional security tools with AI-based solutions that can identify suspicious behavior in real time.

“To address this development, security teams must move beyond traditional warning signals and use intelligent tools that can detect anomalous activity as it occurs. In many cases, it’s a matter of meeting bot with bot,” concludes Varadarajan.

Related Posts

Autonomous AI agents used in cyberattack against Taiwan – new level of automated threats

Suspected China-linked attackers used autonomous AI agents against Taiwanese government systems. The attack shows how AI could change the future of cyber threats.

New report: AI is driving cyberattacks without human control

Check Point Research's AI Security Report 2026 shows that AI can now carry out large parts of cyberattacks without continuous human guidance. The report points to faster…

Disinformation – The most powerful weapon for cybercriminals

Cybersecurity firm Check Point Software claims that we are now in a post-truth era that is reaching new heights as cybercriminal groups increasingly exploit

Questions Answered

How does GreyVibe use AI in its cyberattacks?

Through generative AI tools to create convincing phishing and malicious content.

What defense measures are recommended against AI-assisted attacks?

Strong password management and multi-factor authentication, as well as privilege monitoring.

What effect does AI have on cyber actors' ability to customize campaigns?

AI makes it possible to quickly tailor campaigns to local conditions.

How should security teams address the threat of AI-powered attacks?

By using AI-based solutions that identify suspicious behavior in real time.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT