A Russian-speaking cyber group called GreyVibe, which researchers say operates in the Moscow time zone, is using generative AI tools such as ChatGPT, Google Gemini, and Ideogram AI to carry out advanced cyberattacks against Ukrainian targets. The discovery shows how commercially available AI platforms are increasingly being used to streamline and scale cybercriminal operations.
In a blog post published on May 28, researchers at WithSecure how the group uses specially developed obfuscators to generate fake content and deliver malicious code against military, government, civilian and commercial organizations in Ukraine.
According to the report, GreyVibe uses five main attack chains: PhantomMail, PhantomClick, Princess Club, DroneLink, and Nebo.
AI streamlines established attack methods
Shane Barney, Chief Information Security Officer at Keeper Security, believes that the most remarkable thing is not that the attack methods themselves are new.
– What is remarkable about GreyVibe "It's not that the attack chains are completely new. It's that AI is helping threat actors industrialize them," Barney says.
He explains that AI enables attackers to create more convincing phishing campaigns, fake websites, digital identities, and social engineering materials on a scale that would previously have required significantly greater resources.
“The result is attacks that become more personal, more credible and significantly more difficult for users to distinguish from legitimate communications,” Barney continues.
Focus on identity-based defense
Barney warns that AI-assisted phishing attacks and credential theft campaigns are likely to continue to increase in the coming years.
He recommends that organizations strengthen their identity-based defenses through strong password management, phishing-resistant multi-factor authentication, the principle of least privilege, and continuous monitoring of privileged accounts.
“AI can make social engineering more effective, but the fundamental goal of attackers remains the same: to steal login credentials and gain unauthorized access to systems and data,” says Barney.
Faster adaptation and higher resilience
Sergio Villegas, Senior Managing Analyst II at Bishop Fox, notes that AI and large language models enable threat actors to more quickly develop and adapt their campaigns to local and regional conditions.
He believes that automation of time-consuming tasks has already become an important part of many cyber operations and that the creation of customized decoys and documents is no longer uncommon.
“Speed and precision are the big changes. AI makes it possible to create content that is relevant to specific audiences and situations more quickly,” says Villegas.
He also points out that the ability to reuse or quickly build new malicious infrastructure makes cybercriminal groups more resilient to shutdowns and seizures of cloud and SaaS resources.
“Infrastructure takedowns become less effective when attackers can quickly build new environments and continue their operations,” he says.
Lower thresholds for advanced operations
Yagub Rahimov, CEO of Polygraph AI, believes that the most important conclusion from WithSecure's report is not that yet another threat group is using generative AI.
– The really interesting thing is that AI greatly reduces the time, staffing and specialist expertise required to run cyber operations on a large scale, says Rahimov.
He believes that the development is changing the conditions for both attackers and defenders.
“Actors who previously lacked the resources to conduct credible and long-term operations can now do so significantly faster. At the same time, the same technology is available to both defenders and attackers, which changes the playing field for cybersecurity,” he says.
Security teams must meet AI with AI
Ram Varadarajan, CEO of Acalvio, describes AI as a powerful amplifier for cybercriminal actors.
“The integration of AI effectively gives attackers a new superpower. They can create convincing fake content and tailor-made malware at a speed and scale we haven’t seen before,” says Varadarajan.
He urges organizations to invest more in employee training while complementing traditional security tools with AI-based solutions that can identify suspicious behavior in real time.
“To address this development, security teams must move beyond traditional warning signals and use intelligent tools that can detect anomalous activity as it occurs. In many cases, it’s a matter of meeting bot with bot,” concludes Varadarajan.








