LameHug: first AI-Powered malware linked to Russia’s APT28
ID: 3c84c72a-2217-536a-a253-3da761116e22
STIX ID: report--3c84c72a-2217-536a-a253-3da761116e22
Feed Name: Security Affairs
Threat Score
CERT-UA warns of LameHug, a novel Python-based Windows infostealer attributed with moderate confidence to Russia-linked APT28; it abuses an open-source LLM (Qwen 2.5-Coder-32B-Instruct) via HuggingFace to generate execution commands, collects system info and Office/PDF/TXT files from user folders, and exfiltrates data over SFTP or HTTP POST — delivered in a phishing campaign using a .zip containing a PyInstaller .pif payload and hosted on compromised legitimate services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
