s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.legion_relay

📛 Threat Title

Malware family: LegionRelay

Category: LegionRelay First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.legion_relay`. Printable name: LegionRelay.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (8)

  • web:cyberpress.org

    A previously undocumented Russia-nexus threat group called GREYVIBE has been weaponizing generative AI tools including ChatGPT, Google Gemini, and Ideogram AI to fuel persistent cyberattacks against Ukrainian military, government, civilian, and business entities since at least August 2025, according to new research published by cybersecurity firm WithSecure.

  • web:securityonline.info

    A new analysis from the TEHTRIS Threat Intelligence team details the resurgence of LegionLoader, a sophisticated malware downloader also known as Satacom, CurlyGate, and RobotDropper. This malware has been operating in the shadows, steadily gaining traction and accumulating over 2,000 samples in just a few weeks. According to TEHTRIS researchers, " VirusTotal (VT) retro-hunting and live ...

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.enigmasoftware.com

    Researchers identified design flaws within LegionRelay that inadvertently exposed backend functionality, providing insight into the malware's internal operations. Such mistakes are generally uncommon among highly sophisticated state-sponsored actors, suggesting that GREYVIBE may not represent a traditional intelligence service operation.

  • web:www.fbi.gov

    Threat actors exploit physical and software vulnerabilities in ATMs and deploy malware to dispense cash without a legitimate transaction. The FBI has observed an increase in ATM jackpotting ...

  • web:www.mallory.ai

    LegionRelay is a lightweight PowerShell-based remote access trojan (RAT) associated with the Russia-linked threat cluster GREYVIBE. WithSecure reported it in campaigns active since at least 2025 that targeted Ukraine and Ukraine-related organizations across military, government, civilian, and business sectors.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.