Meet GREYVIBE, the Russia-Linked Hacking Group Using AI to Target Ukraine and Still Making Rookie Mistakes
2026-05-30T02:51:52Z•ff9241de9ce4bd47252d036bc06f0dc566b9219348a71a5b158a717ebb355ae8
AI-assisted malwareAPTAndroid RATBTMOBCISACVE-2026-35616CVE-2026-48172CarnivalFortiClient EMSFortinetFox TempestGREYVIBEKnown Exploited VulnerabilitiesLiteSpeedPII exposureRussia-linkedUkrainecode-signing abusedata breachexploitmobile malwaresecurity-researchsupply-chainvulnerabilityzero-day
What happened
Collection of May 28–29, 2026 security reports: WithSecure tracks a new Russia-linked APT dubbed GREYVIBE using AI-assisted malware to target Ukrainian governmental, military and civil organizations. A researcher publicly dumped six Windows zero-days (three now observed in the wild), prompting debate over disclosure. Multiple actively exploited and KEV-listed vulnerabilities: FortiClient EMS RCE (CVE-2026-35616, CVSS 9.1) is being weaponized in malware campaigns; LiteSpeed cPanel Plugin (CVE-2026-48172, CVSS 10.0) was added to CISA’s Known Exploited Vulnerabilities; CISA also added other flaws
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- ff9241de9ce4bd47252d036bc06f0dc566b9219348a71a5b158a717ebb355ae8
- Enrichment time
- 2026-05-30T02:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.