Meet GREYVIBE, the Russia-Linked Hacking Group Using AI to Target Ukraine and Still Making Rookie Mistakes

2026-05-30T02:51:52Zff9241de9ce4bd47252d036bc06f0dc566b9219348a71a5b158a717ebb355ae8
AI-assisted malwareAPTAndroid RATBTMOBCISACVE-2026-35616CVE-2026-48172CarnivalFortiClient EMSFortinetFox TempestGREYVIBEKnown Exploited VulnerabilitiesLiteSpeedPII exposureRussia-linkedUkrainecode-signing abusedata breachexploitmobile malwaresecurity-researchsupply-chainvulnerabilityzero-day

What happened

Collection of May 28–29, 2026 security reports: WithSecure tracks a new Russia-linked APT dubbed GREYVIBE using AI-assisted malware to target Ukrainian governmental, military and civil organizations. A researcher publicly dumped six Windows zero-days (three now observed in the wild), prompting debate over disclosure. Multiple actively exploited and KEV-listed vulnerabilities: FortiClient EMS RCE (CVE-2026-35616, CVSS 9.1) is being weaponized in malware campaigns; LiteSpeed cPanel Plugin (CVE-2026-48172, CVSS 10.0) was added to CISA’s Known Exploited Vulnerabilities; CISA also added other flaws

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
ff9241de9ce4bd47252d036bc06f0dc566b9219348a71a5b158a717ebb355ae8
Enrichment time
2026-05-30T02:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Meet GREYVIBE, the Russia-Linked Hacking Group Using AI to Target Ukraine and Still Making Rookie Mistakes · Baitaphish