GREYVIBE
Also known as GreyVibe
Reports
4
First seen
May 29, 2026
Last seen
Jun 1, 2026
Motivation
Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×2×2
Ukraine×2
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1566 Phishing ×4T1041 Exfiltration Over C2 Channel ×3T1204 User Execution ×3T1078 Valid Accounts ×2T1195 Supply Chain Compromise ×2T1003 OS Credential Dumping ×2T1113 Screen Capture ×2T1567 Exfiltration Over Web Service ×2T1190 Exploit Public-Facing Application ×2T1598 Phishing for Information ×2T1005 Data from Local System ×2T1059 Command and Scripting Interpreter ×2
Indicators
cve ×39domain ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2026-0257 (exploited)CVE-2026-1402CVE-2026-2332CVE-2026-26980 (exploited)CVE-2026-27771CVE-2026-32996CVE-2026-32997CVE-2026-3593CVE-2026-40933CVE-2026-41089 (exploited)CVE-2026-4115CVE-2026-4480CVE-2026-44930CVE-2026-44962CVE-2026-45659CVE-2026-46775CVE-2026-46839CVE-2026-46840CVE-2026-47783CVE-2026-48095
Recent reports
High