TF-MAL-ps1.legion_relay
📛 Threat Title
Malware family: LegionRelay
Description
ThreatFox malware family `ps1.legion_relay`. Printable name: LegionRelay.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (8)
-
web:cyberpress.org
A previously undocumented Russia-nexus threat group called GREYVIBE has been weaponizing generative AI tools including ChatGPT, Google Gemini, and Ideogram AI to fuel persistent cyberattacks against Ukrainian military, government, civilian, and business entities since at least August 2025, according to new research published by cybersecurity firm WithSecure.
-
web:securityonline.info
A new analysis from the TEHTRIS Threat Intelligence team details the resurgence of LegionLoader, a sophisticated malware downloader also known as Satacom, CurlyGate, and RobotDropper. This malware has been operating in the shadows, steadily gaining traction and accumulating over 2,000 samples in just a few weeks. According to TEHTRIS researchers, " VirusTotal (VT) retro-hunting and live ...
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.enigmasoftware.com
Researchers identified design flaws within LegionRelay that inadvertently exposed backend functionality, providing insight into the malware's internal operations. Such mistakes are generally uncommon among highly sophisticated state-sponsored actors, suggesting that GREYVIBE may not represent a traditional intelligence service operation.
-
web:www.fbi.gov
Threat actors exploit physical and software vulnerabilities in ATMs and deploy malware to dispense cash without a legitimate transaction. The FBI has observed an increase in ATM jackpotting ...
-
web:www.mallory.ai
LegionRelay is a lightweight PowerShell-based remote access trojan (RAT) associated with the Russia-linked threat cluster GREYVIBE. WithSecure reported it in campaigns active since at least 2025 that targeted Ukraine and Ukraine-related organizations across military, government, civilian, and business sectors.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.