GREYVIBE: New Russian-Speaking Cluster Tied to Sustained Operations Against Ukraine
Researchers attribute an August 2025 campaign wave to a previously undocumented actor whose tasking patterns align with Kremlin interests.

A previously undocumented threat cluster — tracked as GREYVIBE — has been linked to a sustained campaign against Ukrainian entities and organizations operating in the Ukraine policy orbit, with activity observed since at least August 2025.
The attribution comes from WithSecure researchers, who assess the operators to be Russian-speaking and working broadly within Russian time zones. Tasking, target selection and operational tempo align with Kremlin state interests, the assessment says.
That is a careful framing. It stops short of a formal nation-state designation.
For regulatory readers, the distinction matters. A private-sector attribution of this kind does not, on its own, trigger sanctions designations or export-control consequences. Those flow from Treasury's Office of Foreign Assets Control or analogous bodies in the EU and UK, which require their own evidentiary thresholds before naming individuals or front entities. GREYVIBE has not, at the time of writing, been the subject of any such designation.
The targeting profile is what brings the activity into the policy conversation.
Ukrainian government bodies, defense-adjacent organizations and entities supporting Ukraine internationally fall within the scope of multiple advisories issued by CISA and partner agencies on Russian state-aligned cyber activity. Critical infrastructure operators with Ukraine exposure should review their obligations under CIRCIA's reporting framework once the final rule takes effect, and EU-based entities should map any incidents against NIS2 Article 23 notification timelines, which require an early warning within 24 hours of a significant incident.
The nature of the intrusions has been characterized as involving automation and machine-learning-assisted tooling, though the specific tradecraft, malware families and initial access vectors have not been publicly enumerated in detail. Indicators of compromise tied to GREYVIBE were not released alongside the initial disclosure.
That limits, for now, what defenders can operationalize.
What policy teams can do is more concrete. Entities providing services to Ukrainian counterparties should confirm their screening procedures against the consolidated OFAC SDN list and the EU consolidated sanctions list, both of which have been expanded repeatedly since February 2022 to cover Russian cyber actors and their enablers. Counsel advising on cyber insurance should also revisit war and hostile-act exclusions, which insurers have tightened in the wake of the Merck/Mondelez litigation.
The disclosure adds another named cluster to an already crowded attribution map that includes APT28, Sandworm, Gamaredon and Turla. Whether GREYVIBE represents a genuinely new organizational entity, a rebrand, or a subordinate team within an existing service will likely take further reporting to establish.
For now, the name is a placeholder around which defenders and policymakers can organize observations.



