LAMEHUG

MITRE ATT&CK: S9035 View on attack.mitre.org

Aliases: PROMPTSTEAL, LAMEHUG

First seen
2025-07-01 00:00:00
Malware type
credential-stealer, spyware
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:17:07

Targeted industries: government-and-public-sector

Targeted regions: country_code:ua

Context

LAMEHUG is Python-based information stealer first identified in July 2025 by Ukraine's Computer Emergency Response Team (CERT-UA) in phishing emails targeting Ukrainian government officials. LAMEHUG is the first known malware to integrate artificial intelligence (AI) directly into its attack workflow by querying large language models (LLMs) hosted on Hugging Face to dynamically generate reconnaissance, data theft, and system manipulation commands in real time. LAMEHUG has been attributed to APT28.

Detection coverage

  • 377 Sigma rules

Malware & tools used

  • Exfiltration Over C2 Channel (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Data Encoding (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Domain Account (attack-pattern)
  • Domain Trust Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Domain Groups (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Malicious File (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Automated Collection (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Local Data Staging (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Python (attack-pattern)

Used by threat actors

Reports & references

  • cloud.google.com — Threat Actor Usage Of Ai Tools (report)
  • malpedia.caad.fkie.fraunhofer.de — Py.Lamehug (report)
  • catonetworks.com — Cato Ctrl Threat Research Analyzing Lamehug (report)
  • CERT-UA — 6284730 (report)
  • MITRE ATT&CK — S9035 (report)
  • splunk.com — Lamehug Ai Driven Malware Llm Cyber Intrusion Analysis (report)

External references