{"id":11634,"date":"2026-05-28T10:04:44","date_gmt":"2026-05-28T09:04:44","guid":{"rendered":"https:\/\/www.withsecure.com\/resources-hub\/press-releases\/withsecure-uncovers-russia-nexus-threat-group-using-ai-to-target-ukraine-and-european-organisations\/"},"modified":"2026-06-02T11:32:46","modified_gmt":"2026-06-02T10:32:46","slug":"withsecure-uncovers-russia-nexus-threat-group-using-ai-to-target-ukraine-and-european-organisations","status":"publish","type":"pressroom","link":"https:\/\/www.withsecure.com\/jp-ja\/resources-hub\/press-releases\/withsecure-uncovers-russia-nexus-threat-group-using-ai-to-target-ukraine-and-european-organisations\/","title":{"rendered":"WithSecure uncovers Russia-nexus threat group using AI to target Ukraine and European organisations"},"content":{"rendered":"<section\n    class=\"wp-block-one-column-block edwp-block js-wp-block-one-column-block wp-block-one-column-block--content-1 wp-block-one-column-block--meta-sharing layout--spacing-xxxxl-top layout--spacing-xl-bottom\"\n    >\n    <div class=\"wp-block-one-column-block__container\">\n                                                                                                                            <div class='wp-block-one-column-block__meta-sharing-grid'><div class=\"wp-component-content wp-component-content--default wp-block-one-column-block__content fade-in\">\n            <h1 class=\"wp-component-heading text--h2 wp-component-content__title\">\n    WithSecure uncovers Russia-nexus threat group using AI to target  <span class=\"blue-text\">Ukraine and European organisations<\/span><\/h1>                    <div class=\"wp-component-content__inner\">\n                                                    <div class=\"wp-component-content__meta\">\n                                                                            <span class=\"wp-component-content__meta-categories\">\n                                                                    <span class=\"wp-component-content__meta-category\">\n                                        AI                                    <\/span>\n                                                                    <span class=\"wp-component-content__meta-category\">\n                                        Research                                    <\/span>\n                                                                    <span class=\"wp-component-content__meta-category\">\n                                        Threat intelligence                                    <\/span>\n                                                            <\/span>\n                                                                                                    <span class=\"wp-component-content__meta-date\">\n                                28 5\u6708, 2026                            <\/span>\n                                                                    <\/div>\n                                            <\/div>\n                <\/div><section\n    class=\"wp-block-sharing-icons edwp-block wp-block-sharing-icons--disable-border wp-block-sharing-icons--content-1 wp-block-sharing-icons--disable-container wp-block-one-column-block__sharing fade-in wp-block-one-column-block__sharing fade-in\"\n    >\n    <div class=\"wp-block-sharing-icons__container\">\n        <div class=\"wp-block-sharing-icons__inner\">\n                            <p class=\"wp-block-sharing-icons__title fade-in\">\n                    \u30b7\u30a7\u30a2\u3059\u308b                <\/p>\n                        <div class=\"wp-component-socials wp-component-socials--dark-mode\">\n    \n            <a href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https:\/\/www.withsecure.com\/jp-ja\/resources-hub\/press-releases\/withsecure-uncovers-russia-nexus-threat-group-using-ai-to-target-ukraine-and-european-organisations\/&#038;title=WithSecure%20uncovers%20Russia-nexus%20threat%20group%20using%20AI%20to%20target%20Ukraine%20and%20European%20organisations\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link\" title=\"Linkedin\u3067\u5171\u6709\u3059\u308b\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#linkedin'><\/use>\n            <\/svg>        <\/a>\n    \n            <a href=\"http:\/\/x.com\/share?text=WithSecure uncovers Russia-nexus threat group using AI to target Ukraine and European organisations&#038;url=https:\/\/www.withsecure.com\/jp-ja\/resources-hub\/press-releases\/withsecure-uncovers-russia-nexus-threat-group-using-ai-to-target-ukraine-and-european-organisations\/\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link wp-component-socials__link--twitter\" title=\"\u30c4\u30a4\u30c3\u30bf\u30fc\u3067\u5171\u6709\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#x'><\/use>\n            <\/svg>        <\/a>\n    \n    \n    <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<\/div>                                                                                <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-one-column-block edwp-block js-wp-block-one-column-block wp-block-one-column-block--content-1 layout--spacing-xxxl-bottom\"\n    >\n    <div class=\"wp-block-one-column-block__container\">\n                                                                                                                                    <div class=\"wp-component-image__wrapper wp-block-one-column-block__image fade-in\">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1600\" height=\"640\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Withsecure_People_Tech.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-content-25-1 wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Withsecure_People_Tech.png.webp 1600w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Withsecure_People_Tech-300x120.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Withsecure_People_Tech-1024x410.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Withsecure_People_Tech-768x307.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Withsecure_People_Tech-1536x614.png.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Withsecure_People_Tech-447x179.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Withsecure_People_Tech-365x146.png.webp 365w\" sizes=\"auto, (max-width: 1600px) 100vw, 1600px\" \/>                                                    <\/figure>\n                    <\/div>\n                                                                                <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-two-column-block edwp-block js-wp-block-two-column-block wp-block-two-column-block--content-1 wp-block-two-column-block__left--align-y-top wp-block-two-column-block__right--align-y-top wp-block-two-column-block--split-sidebar layout--none-top layout--spacing-xxxl-bottom\"\n    data-block-id=\"block_945819647f5515445172d05ef56842eb\"\n    >\n    <div class=\"wp-block-two-column-block__container row-load\">\n                                                        <div class=\"wp-block-two-column-block__left\">\n                                    <div class=\"wp-component-contacts-list wp-block-two-column-block__contacts\">\n                    <p class=\"wp-component-contacts-list__title js-contacts-list-nav-title\">\n                WithSecure media relations            <\/p>\n        \n        <div class=\"wp-component-contacts-list__items\">\n                            <div class=\"wp-component-contacts-list__item\">\n                                            <p class=\"wp-component-contacts-list__item-title\">\n                            WithSecure PR                        <\/p>\n                    \n                                            <p class=\"wp-component-contacts-list__email\">\n                            <a\n                                class=\"wp-component-contacts-list__email-link\"\n                                href=\"mailto:pr@withsecure.com\"\n                            >\n                                pr@withsecure.com                            <\/a>\n                        <\/p>\n                    \n                                    <\/div>\n                    <\/div>\n    <\/div>\n<section\n    class=\"wp-block-sharing-icons edwp-block wp-block-sharing-icons--disable-border wp-block-sharing-icons--disable-container wp-block-two-column-block__share wp-block-two-column-block__hide-mobile wp-block-two-column-block__share wp-block-two-column-block__hide-mobile\"\n    >\n    <div class=\"wp-block-sharing-icons__container\">\n        <div class=\"wp-block-sharing-icons__inner\">\n                            <p class=\"wp-block-sharing-icons__title fade-in\">\n                    Share this                <\/p>\n                        <div class=\"wp-component-socials wp-component-socials--dark-mode\">\n    \n            <a href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https:\/\/www.withsecure.com\/jp-ja\/resources-hub\/press-releases\/withsecure-uncovers-russia-nexus-threat-group-using-ai-to-target-ukraine-and-european-organisations\/&#038;title=WithSecure%20uncovers%20Russia-nexus%20threat%20group%20using%20AI%20to%20target%20Ukraine%20and%20European%20organisations\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link\" title=\"Linkedin\u3067\u5171\u6709\u3059\u308b\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#linkedin'><\/use>\n            <\/svg>        <\/a>\n    \n            <a href=\"http:\/\/x.com\/share?text=WithSecure uncovers Russia-nexus threat group using AI to target Ukraine and European organisations&#038;url=https:\/\/www.withsecure.com\/jp-ja\/resources-hub\/press-releases\/withsecure-uncovers-russia-nexus-threat-group-using-ai-to-target-ukraine-and-european-organisations\/\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link wp-component-socials__link--twitter\" title=\"\u30c4\u30a4\u30c3\u30bf\u30fc\u3067\u5171\u6709\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#x'><\/use>\n            <\/svg>        <\/a>\n    \n    \n    <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n                <\/div>\n                                                <div class=\"wp-block-two-column-block__right\">\n                                <div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><em>New research exposes GREYVIBE \u2013 a persistent, AI-powered Russia-nexus group targeting military, government, and business entities across Ukraine and Europe since mid-2025.<\/em><\/p>\n<p><b>Helsinki, Finland \u2013 May 28, 2026:<\/b>\u00a0WithSecure, Europe\u2019s trusted cybersecurity partner, today published new threat intelligence revealing a previously undocumented Russia-nexus threat group, tracked as GREYVIBE. Active since at least August 2025, the group has conducted persistent operations targeting military personnel, government bodies, and businesses across Ukraine, with additional targeting of European organisations. GREYVIBE\u2019s activities align with Russian state intelligence-gathering objectives in the context of the ongoing Russia\u2013Ukraine war.<\/p>\n<p>The research documents GREYVIBE\u2019s systematic use of generative AI (GenAI) and large language models (LLMs) across every phase of their operations \u2013 from building fake websites and crafting lures to developing custom malware and generating post-compromise tooling. WithSecure also identified indicators placing the group at the intersection of state-aligned activity and the broader cybercrime ecosystem.<\/p>\n<p>The findings carry direct relevance for organisations across Europe. AI is lowering the barrier to entry for espionage-grade operations \u2013 groups that would previously have lacked the capability to develop custom malware and mount sustained campaigns can now do so with AI assistance. The threshold for targeting has dropped, and mid-market organisations that may have considered themselves below the radar of nation-state activity should take note.<\/p>\n<h3>AI as an attack accelerator<\/h3>\n<p>Evidence points to the use of multiple AI platforms \u2013 including ChatGPT, Google Gemini, and image generation tools \u2013 to produce lure sites, develop custom remote access trojans, build obfuscation frameworks, and generate post-compromise scripts. The breadth and consistency of usage suggests deliberate integration into the group\u2019s operational workflow, not ad-hoc experimentation. Crucially, design flaws in LLM-assisted malware allowed WithSecure to monitor GREYVIBE\u2019s activity across victim machines for several months \u2013 providing rare, sustained visibility into the group\u2019s targeting and behaviour.<\/p>\n<p>\u201cWhat sets GREYVIBE apart is not raw technical skill, but operational ambition powered by AI. The group uses generative AI to punch above its weight \u2013 accelerating development, filling capability gaps, and generating a largely fresh operational profile that complicates tracking and attribution. It\u2019s a preview of how lower-sophistication actors will increasingly operate\u201d, says <b>Mohammad Kazem Hassan Nejad<\/b>, Senior Threat Intelligence Researcher, WithSecure<\/p>\n<h3>Key findings<\/h3>\n<ul>\n<li>Persistent targeting of Ukrainian military, government, civilian, and business entities since August 2025.<\/li>\n<li>Systematic AI use across lure creation, malware development, infrastructure setup, and post-compromise tooling \u2013 integrated throughout operations, not used in isolation.<\/li>\n<li>Multiple attack vectors, including spear-phishing emails, fake CAPTCHA pages, and social engineering via Telegram using fake female personas.<\/li>\n<li>Custom malware suite including two generations of a PowerShell-based RAT (PhantomRelay), Android spyware (FallSpy), and a secondary RAT (LegionRelay) \u2013 all assessed to have been developed with LLM assistance.<\/li>\n<li>High-confidence attribution to Russian-speaking operators in the Moscow time zone, with targeting and objectives aligned with Russian state interests.<\/li>\n<li>Indicators of ties to the cybercrime ecosystem, with possible proximity to tooling linked to the former TrickBot syndicate.<\/li>\n<li>Repeated operational security failures suggest a low-to-moderately sophisticated group \u2013 a reminder that less capable actors can still pose meaningful threats.<\/li>\n<\/ul>\n<p>The full GREYVIBE research report is available at <a id=\"OWA9933b192-589c-07da-b457-b08c8911496f\" class=\"x_OWAAutoLink\" title=\"https:\/\/labs.withsecure.com\/publications\/greyvibe\" href=\"https:\/\/eur03.safelinks.protection.outlook.com\/?url=https%3A%2F%2Flabs.withsecure.com%2Fpublications%2Fgreyvibe&amp;data=05%7C02%7Cross.tweedie%40elixirr.com%7C2dd1bf2c0e704817e3e808debc8ef9fb%7C7d93cd9058984384a827507bc06c9089%7C0%7C0%7C639155519429372433%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;sdata=4wXq96%2BtDFpClMrzpi2NztFUthzOCgBQw3g1l%2BLUVu4%3D&amp;reserved=0\" data-auth=\"NotApplicable\" target=\"_blank\" rel=\"noopener\">https:\/\/labs.withsecure.com\/publications\/greyvibe<\/a>.<\/p>\n<p>For a deeper technical dive, join researcher Mohammad Kazem Hassan Nejad as he presents the findings in an upcoming webinar on June 17, 2026. Register at <a id=\"OWA686e1ed6-1195-4a92-de0a-253382e343a5\" class=\"x_OWAAutoLink\" title=\"https:\/\/withsecure.videosync.fi\/2026-06-17-74zx3ymlnn\/register\" href=\"https:\/\/eur03.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwithsecure.videosync.fi%2F2026-06-17-74zx3ymlnn%2Fregister&amp;data=05%7C02%7Cross.tweedie%40elixirr.com%7C2dd1bf2c0e704817e3e808debc8ef9fb%7C7d93cd9058984384a827507bc06c9089%7C0%7C0%7C639155519429409696%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;sdata=Q%2BeMOtP4%2BQRVDthWunNRF%2BLZXWaFgP3UPx1PI1rsjSk%3D&amp;reserved=0\" data-auth=\"NotApplicable\" target=\"_blank\" rel=\"noopener\">https:\/\/withsecure.videosync.fi\/2026-06-17-74zx3ymlnn\/register<\/a>.<\/p>\n<\/div>\n<section\n    class=\"wp-block-sharing-icons edwp-block wp-block-sharing-icons--disable-border wp-block-sharing-icons--disable-container wp-block-two-column-block__share wp-block-two-column-block__mobile-after-right wp-block-two-column-block__share wp-block-two-column-block__mobile-after-right\"\n    >\n    <div class=\"wp-block-sharing-icons__container\">\n        <div class=\"wp-block-sharing-icons__inner\">\n                            <p class=\"wp-block-sharing-icons__title fade-in\">\n                    Share this                <\/p>\n                        <div class=\"wp-component-socials wp-component-socials--dark-mode\">\n    \n            <a href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https:\/\/www.withsecure.com\/jp-ja\/resources-hub\/press-releases\/withsecure-uncovers-russia-nexus-threat-group-using-ai-to-target-ukraine-and-european-organisations\/&#038;title=WithSecure%20uncovers%20Russia-nexus%20threat%20group%20using%20AI%20to%20target%20Ukraine%20and%20European%20organisations\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link\" title=\"Linkedin\u3067\u5171\u6709\u3059\u308b\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#linkedin'><\/use>\n            <\/svg>        <\/a>\n    \n            <a href=\"http:\/\/x.com\/share?text=WithSecure uncovers Russia-nexus threat group using AI to target Ukraine and European organisations&#038;url=https:\/\/www.withsecure.com\/jp-ja\/resources-hub\/press-releases\/withsecure-uncovers-russia-nexus-threat-group-using-ai-to-target-ukraine-and-european-organisations\/\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link wp-component-socials__link--twitter\" title=\"\u30c4\u30a4\u30c3\u30bf\u30fc\u3067\u5171\u6709\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#x'><\/use>\n            <\/svg>        <\/a>\n    \n    \n    <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n                <\/div>\n                        <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-cta-banner edwp-block js-wp-block-cta-banner wp-block-cta-banner--style-icon wp-block-cta-banner--no-image layout--spacing-xxxl-top layout--spacing-xxxl-bottom\"\n    >\n    <div class=\"wp-block-cta-banner__container\">\n        <div class=\"wp-block-cta-banner__box row-load\">\n            <div class=\"wp-component-content wp-component-content--help-text wp-component-content--dark wp-block-cta-banner__content\">\n                        <div class=\"wp-component-content__inner\">\n                <h2 class=\"wp-component-heading text--h2 wp-component-heading--dark wp-component-content__title\">\n    What <span class=\"blue-text\">next?<\/span><\/h2>                                    <div class=\"wp-component-content__content wysiwyg wysiwyg--dark\">\n                        <div class=\"wp-component-paragraph wp-component-paragraph--dark\">\n    <p class=\"text--p-medium\">Discover WithSecure\u2122 Elements Exposure Management.<br \/>\n&#8211; No credit card required. No obligations.No complexity.<\/p>\n<\/div>\n                    <\/div>\n                            <\/div>\n                            <div class=\"wp-component-content__buttons\">\n                <a class=\"wp-component-button btn btn--primary btn--dark\" href=\"https:\/\/www.withsecure.com\/en\/contact-us\/\">Contact us<\/a>            <\/div>\n                <\/div>                    <\/div>\n    <\/div>\n<\/section>\n\n\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":3,"featured_media":0,"template":"","categories":[433,184,316],"class_list":["post-11634","pressroom","type-pressroom","status-publish","hentry","category-ai","category-research","category-threat-intelligence"],"acf":[],"card":"<div class=\"wp-component-card-insight js-card-link wp-component-card-insight--highlighted\">\n    <div class=\"wp-component-card-insight__image-wrapper\">\n        <img width=\"618\" height=\"440\" src=\"https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder.jpg\" class=\"wp-component-card-insight__image\" alt=\"\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder.jpg 618w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder-300x214.jpg 300w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder-447x318.jpg 447w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder-205x146.jpg 205w\" sizes=\"auto, (max-width: 618px) 100vw, 618px\" \/>                    <p class=\"wp-component-card-insight__content-type\">\u30d7\u30ec\u30b9\u30ea\u30ea\u30fc\u30b9<\/p>\n            <\/div>\n    <div class=\"wp-component-card-insight__content\">\n                    <div class=\"wp-component-card-insight__meta\">\n                <div class=\"wp-component-card-insight__categories\">\n                                            <span class=\"wp-component-card-insight__category\">AI<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Research<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Threat intelligence<\/span>\n                                    <\/div>\n            <\/div>\n                            <h3 class=\"wp-component-card-insight__title\">WithSecure uncovers Russia-nexus threat group using AI to target Ukraine and European organisations<\/h3>\n                                                    <div class=\"wp-component-card-insight__button-wrapper\">\n                <a class=\"wp-component-button btn btn--primary btn--dark wp-component-card-insight__button btn--small\" href=\"https:\/\/www.withsecure.com\/jp-ja\/resources-hub\/press-releases\/withsecure-uncovers-russia-nexus-threat-group-using-ai-to-target-ukraine-and-european-organisations\/\">\u3082\u3063\u3068\u8aad\u3080<\/a>            <\/div>\n            <\/div>\n<\/div>","_links":{"self":[{"href":"https:\/\/www.withsecure.com\/jp-ja\/wp-json\/wp\/v2\/pressroom\/11634","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.withsecure.com\/jp-ja\/wp-json\/wp\/v2\/pressroom"}],"about":[{"href":"https:\/\/www.withsecure.com\/jp-ja\/wp-json\/wp\/v2\/types\/pressroom"}],"author":[{"embeddable":true,"href":"https:\/\/www.withsecure.com\/jp-ja\/wp-json\/wp\/v2\/users\/3"}],"wp:attachment":[{"href":"https:\/\/www.withsecure.com\/jp-ja\/wp-json\/wp\/v2\/media?parent=11634"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.withsecure.com\/jp-ja\/wp-json\/wp\/v2\/categories?post=11634"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}