Find notable cyber news and cases, enriched with sources, timelines, and signals.

GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations

Campaign
First reported
Last updated
Happening score
H score 39
2 unique sources, 2 articles

Summary

Hide ▲

GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian, and business targets. The operation has been active since at least August 2025 and uses multiple lure-and-delivery chains to push phishing, malware, and credential-theft workflows. Researchers linked the activity to a likely Russian-aligned operator set, though the group’s exact state affiliation remains unconfirmed.

Related Happenings

Russian Coms caller-ID spoofing platform evolved into a sold criminal service

Threat Actor Meta
H score43 First: 13.07.2026 16:23 Last: 13.07.2026 16:23 Sources 1

About this happening: Investigators documented Russian Coms as a monetized caller-ID spoofing platform that let criminals hide their identity and scale scam calls across more than 107 countries...

Russian FSB Center 16 router intrusion campaign

Campaign
H score40 First: 13.07.2026 12:32 Last: 13.07.2026 12:32 Sources 1

About this happening: A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...

Silver Fox counterfeit-installer SEO-poisoning campaign across Asia

Campaign
H score32 First: 10.07.2026 16:15 Last: 10.07.2026 16:15 Sources 1

About this happening: Silver Fox is running a counterfeit-installer SEO-poisoning campaign that delivers malware across Asia and puts technology, education, and state-owned enterprise...

O-UNC-066 / Pink Microsoft Entra passkey vishing campaign

Campaign
H score37 First: 08.07.2026 19:47 Last: 08.07.2026 19:47 Sources 1

About this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...

Scattered Spider reclassified as a decentralized collective of independent clusters

Threat Actor Meta
H score26 First: 07.07.2026 17:00 Last: 07.07.2026 17:00 Sources 1

About this happening: Scattered Spider has been reclassified as a decentralized cybercrime collective, changing how its persistence and resilience are understood. The shift suggests independe...

Timeline

  1. 28.05.2026 03:00 3 articles · 1mo ago

    WithSecure links GreyVibe to an AI-assisted cyberespionage campaign against Ukraine-linked organizations

    Initial Disclosure

    WithSecure identified GreyVibe as a likely Russian threat group conducting cyberespionage against Ukrainian or Ukraine-related organizations, with activity active since at least August 2025 and discovered in January 2026. The operation used AI-generated lures and multiple custom tools to support spear-phishing, fake CAPTCHA/ClickFix pages, fake websites, and malware delivery across military, government, civilian, and business targets.

    Show sources