An underground forum post claims to leak original APT43 backdoors, rootkits, and zero-day exploits. In reality, the campaign is a malicious honeypot targeting security researchers and enterprise defenders with North Korean malware.
The hybrid threat group GreyVibe is combining generative AI social engineering lures with custom-built PowerShell RATs and Android spyware. This post provides a deep technical analysis of their campaigns and defensive hunt guidance.


Redirection to fake CAPTCHA / verification pages mimicking Zoom or LAPAS
Victim is prompted to press Win+R, paste a malicious command with Ctrl+V, and hit Enter
Obfuscated PowerShell loader fires, leveraging LOOKVALPS or DAYLIGHT
PhantomRelay RAT executes, establishing an interactive shell with the C2
If your team may be exposed to a similar threat, FemtoSec can help validate blast radius, prioritize remediation, and connect the issue to a practical security program.
An underground forum post claims to leak original APT43 backdoors, rootkits, and zero-day exploits. In reality, the campaign is a malicious honeypot targeting security researchers and enterprise defenders with North Korean malware.

August 5, 2026
A devastating self-propagating npm supply chain worm has compromised over 800 packages, including the keyv library. The malware targets developer tools, exfiltrates AWS and Kubernetes secrets, and installs a destructive dead-man's switch.

October 5, 2026
Underground advertisements offering commercial licenses for XWorm V3.0 highlight the persistent threat of modular Remote Access Trojans capable of surveillance, keylogging, and complete Windows endpoint compromise across enterprise environments.
Defenders confronting the emerging threat of the GreyVibe campaign must immediately audit system-wide script execution policies and isolate unauthorized interactive shells. This hybrid espionage cluster, with active operations tracked since at least August 2025, represents a distinct shift in how adversaries leverage commercial generative artificial intelligence to scale operational capabilities. By combining generative AI lures with custom-built PowerShell malware, the group targets government, military, and civilian entities across multiple regions.
If indicators of compromise are identified, security teams must act quickly to contain the threat and limit lateral movement:
Enforce Constrained Language Mode: Enable PowerShell Constrained Language Mode (CLM) across all non-developer endpoints to limit dynamic API access and prevent the execution of obfuscated memory payloads.
Disable Windows Script Host: Turn off wscript.exe and cscript.exe globally to neutralize JavaScript-based double-extension loaders, such as .js files masked as documents.
Terminate Active Browser Sessions: If an endpoint is suspected of compromise, immediately invalidate and rotate all active session cookies, Telegram desktop tokens, and WhatsApp sessions to neutralize credential theft.
The threat model operates at the intersection of nation-state espionage and opportunistic cybercrime. While the group exhibits operational security gaps, such as uploading testing samples to public scanning platforms, their systematic deployment of AI-powered spear-phishing lures and custom evasion toolkits makes them a serious threat to enterprise attack surfaces. Security leaders must proactively evaluate their external footprint using Attack Surface Management to detect exposed credentials and unauthorized access points that these threat actors routinely exploit.
GreyVibe is a Russia-nexus threat group whose activities closely align with Russian state interests. Extensive threat intelligence research indicates that the operators are Russian-speaking, with infrastructure and command-and-control servers configured to UTC+3 (Moscow time). While the group maintains a primary focus on Ukrainian or Ukraine-related organizations, its targeting has expanded to other global regions.
Despite their alignment with state espionage goals, researchers assess that GreyVibe lacks the rigid operational discipline characteristic of mature nation-state Advanced Persistent Threat (APT) groups. For instance, the deployment of cryptocurrency miners on compromised systems and the utilization of custom ISO builders linked to former members of cybercriminal organizations, such as UAC-0098 (a group with historical ties to TrickBot), point to a hybrid composition. The threat actor likely consists of active or former cybercriminals who have been co-opted or task-directed by state-affiliated entities.
The group compensates for any lack of sophisticated zero-day capabilities by mastering rapid, AI-driven social engineering. By utilizing platforms like ChatGPT, Google Gemini, and Ideogram AI, GreyVibe generates hyper-realistic text lures, localized phishing pages, and custom graphical assets that easily bypass traditional security awareness filters. To defend against such highly tailored threats, organizations should deploy advanced, continuous Security Awareness Training to help employees identify artificial intelligence-assisted lures.
The threat group runs five concurrent campaigns, each tailored to specific vectors and operational objectives:
The PhantomMail campaign targets key personnel through highly specific spear-phishing emails containing malicious ZIP or RAR archives hosted on public cloud repositories, including Google Drive and 4sync. When opened, these archives extract double-extension JavaScript loaders, such as .pdf.js or .rar.js, which are heavily obfuscated using the custom LOOKVALJS or TEASOUP engines. To deceive the user, a decoy PDF or fake system error is displayed on screen while a script launcher silently executes in the background to install the PhantomRelay remote access trojan (RAT).
Leveraging fake CAPTCHA and ClickFix verification pages, this campaign redirects users to domains designed to look like legitimate services, such as Zoom and LAPAS. The victim is greeted with a fake Cloudflare verification prompt instructing them to press the Windows key + R, paste an encoded command into the Run dialog box, and press Enter. This social engineering trick directly executes a custom PowerShell command, bypassing browser sandbox protections to deploy the PhantomRelay RAT.
Primarily targeting military and defense personnel, this campaign uses fraudulent dating portals and fake female Telegram personas to build trust. Recent iterations have incorporated WebRTC-based live call features to increase credibility before delivering the payload. For Android devices, victims are directed to download a malicious application package (princess.apk) containing the FallSpy spyware. For Windows devices, the actors deliver JavaScript-based loaders that deploy the LegionRelay RAT.
The DroneLink campaign leverages fake military charity sites, specifically focusing on FPV drone fundraising. The underlying infrastructure and custom tooling are shared with the PrincessClub campaign. Once a user is enticed to download a fake software update or connectivity tool on the decoy site, the compromised system is loaded with LegionRelay alongside legitimate administrative utilities like WireGuard and ZAPiXDESK, which the actors use for session hijacking.
The Nebo campaign features clone login pages that mimic Russian tactical military communications portals like SPO Nebo. This campaign targets frontline personnel, acting as a direct credential harvester and a gateway for secondary execution. Depending on the victim platform, the infection chain deploys FallSpy on Android or LegionRelay on Windows endpoints.
GreyVibe's tooling highlights their heavy reliance on large language models (LLMs) to write, optimize, and obfuscate code.
The threat actor employs a custom development pipeline designed to generate new obfuscation variants to evade static signature detection:
LOOKVALPS / LOOKVALJS: Early-stage PowerShell and JavaScript obfuscators that rely on randomized variable names, opaque predicates, and environment checks to break sandbox analysis.
DAYLIGHT / TEASOUP: Advanced successors built with LLM assistance starting in late 2025 and early 2026. These engines systematically encrypt loader structures and make extensive use of dynamic API resolution to hinder reverse-engineering efforts.
The group relies primarily on two PowerShell-based remote access trojans:
PhantomRelay: A modular, WebSocket-based RAT. Upon initial execution, it performs extensive environment fingerprinting, validates system name white-lists to block sandboxes, and establishes an active WebSocket connection to its command-and-control server. The malware also includes a dedicated USB propagation module (WUDFHost.ps1) that drops launcher scripts in %PROGRAMDATA% iles to compromise connected storage drives.
LegionRelay: A lightweight post-compromise RAT that communicates via standard REST APIs. LegionRelay supports screenshot capturing, file and directory enumeration, browser credential theft, and persistent RDP setups. It also exfiltrates local Telegram and WhatsApp session databases to allow the attackers to hijack instant messaging accounts without triggering multifactor authentication. Interestingly, because parts of LegionRelay's backend databases were developed with AI assistance, researchers identified design flaws that allowed investigators to intercept and expose portions of the group's infrastructure.
Deployed in mobile-focused campaigns, FallSpy is a specialized surveillance tool designed to collect comprehensive tactical intelligence. Once installed on a device, the spyware exfiltrates contact lists, SMS messages, call histories, real-time GPS coordinates, connected Wi-Fi SSIDs, device storage contents, and SIM card details.
Free exposure check
Dark Web Scanner
check dark web mentions, compromised account indicators, malware log signals, public breach exposure, and recent underground market activity for your domain.
Analysis of GreyVibe's behavioral patterns reveals close alignment with the following MITRE ATT&CK techniques:
T1566.002 (Phishing: Malicious Link): Delivering public cloud storage links via target emails.
T1204.001 (User Execution: Malicious Link): Tricking targets into clicking malicious links on fake dating portals and military charity sites.
T1059.001 (Command and Scripting Interpreter: PowerShell): Running PowerShell scripts as the primary engine for LegionRelay and PhantomRelay.
T1027 (Obfuscated Files or Information): Relying on DAYLIGHT, TEASOUP, and LOOKVAL utilities to encrypt payload files.
T1547.001 (Boot or Logon Autostart Execution): Creating persistent shortcut files within startup directories.
T1113 (Screen Capture): Grabbing and transmitting Base64-encoded screen captures.
T1539 (Steal Web Session Cookie): Hijacking local browser directories to capture active session tokens and bypass multi-factor security controls.
To detect GreyVibe activity within your environment, security operations teams should implement the following hunting queries and verification steps:
Look for instances where conhost.exe is spawned with the --headless flag. This is an unusual execution behavior when initiated by local users or standard scripting interpreters and often indicates an automated script attempting to hide its graphical window.
Attackers use PowerShell commands to hide their tracks. Search process creation logs for command lines containing:
Set-PSReadlineOption -HistorySaveStyle SaveNothingor
Remove-Module PSReadlineThese commands prevent Windows from logging command history, a classic sign of active system tampering.
GreyVibe attempts to conceal newly created administrative accounts by hiding them from the Windows login interface. Monitor modifications to the following registry path:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListAny unauthorized usernames added to this key should be investigated immediately as potential persistent backdoors.