LAMEHUG

S9035

Malware.View on attack.mitre.org

About this malware

LAMEHUG is Python-based information stealer first identified in July 2025 by Ukraine's Computer Emergency Response Team (CERT-UA) in phishing emails targeting Ukrainian government officials. LAMEHUG is the first known malware to integrate artificial intelligence (AI) directly into its attack workflow by querying large language models (LLMs) hosted on Hugging Face to dynamically generate reconnaissance, data theft, and system manipulation commands in real time. LAMEHUG has been attributed to APT28.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1005
Data from Local System

LAMEHUG has the ability to collect system information and files of interest from compromised systems.

T1007
System Service Discovery

LAMEHUG can gather service information on targeted systems.

T1016
System Network Configuration Discovery

LAMEHUG can enumerate network information on compromised hosts.

T1033
System Owner/User Discovery

LAMEHUG can use `whoami` to enumerate the system user.

T1036.005
Match Legitimate Resource Name or Location

LAMEHUG payloads have been disguised with legitimate looking filenames including AI_generator_uncensored_Canvas_PRO_v0.9.exe and AI_image_generator_v0.95.exe.

T1041
Exfiltration Over C2 Channel

LAMEHUG can exfiltrate collected system information and documents to C2.

T1047
Windows Management Instrumentation

LAMEHUG can use wmic to collect system information.

T1057
Process Discovery

LAMEHUG can gather process information on targeted systems.

T1059.003
Windows Command Shell

LAMEHUG can use `cmd.exe` to display a decoy file to spearphishing victims.

T1059.006
Python

LAMEHUG can use Python scripts for execution.

T1069.002
Domain Groups

LAMEHUG can use dsquery to gather domain group information.

T1071.001
Web Protocols

LAMEHUG can use HTTP POST requests to exfiltrate data from compromised hosts to C2.

T1074.001
Local Data Staging

LAMEHUG can save collected data and files of interest in `C:\ProgramData\info\` to consolidate for exfiltration.

T1082
System Information Discovery

LAMEHUG has the ability to execute Windows commands returned from C2 to gather system information.

T1083
File and Directory Discovery

LAMEHUG can target directories on victim machines for file collection.

View all 25 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. Cato LAMEHUG JUL 2025 Open source
    Simonovich, V. (2025, July 23). Cato CTRL™ Threat Research: Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 (Fancy Bear) . Retrieved April 21, 2026.
  2. Nov AI Threat Tracker Open source
    Google Threat Intelligence Group. (2025, November 5). GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools. Retrieved March 31, 2026.
  3. Splunk LAMEHUG SEP 2025 Open source
    Conteras, T., Splunk Research Team. (2025, September 25). From Prompt to Payload: LAMEHUG’s LLM-Driven Cyber Intrusion. Retrieved April 21, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.