216.73.216.233

Analyzing LAMEHUG

· Published 24/08/2025 11:22 · Modified 25/08/2025 11:02

Export JSON

Essential information

Published
24/08/2025 11:22
Modified
25/08/2025 11:02
Tags
2025-08-24 ai-generated commands apt28 exfiltration lamehug llm phishing proof-of-concept reconnaissance ukraine
Related entities
1 intrusion sets (apt), 13 techniques (mitre), 1 malware, 2 others

Description

, discovered on July 10, 2025, is the first known malware integrating large language model capabilities into its attack methodology. Attributed to (Fancy Bear) with moderate confidence, it targeted Ukrainian government officials through emails containing malicious executables. The malware uses the Qwen2.5-Coder-32B-Instruct via Hugging Face's API to generate dynamic attack commands. Multiple variants were identified, with different data methods. The attack appears to be a exploration of integration in state-sponsored cyber operations, demonstrating sophisticated capabilities through . This development signals a new era of AI-incorporated malware operations, posing challenges for traditional cybersecurity approaches.

External references