logo

LameHug: first AI-Powered malware linked to Russia’s APT28

ID: 3c84c72a-2217-536a-a253-3da761116e22

STIX ID: report--3c84c72a-2217-536a-a253-3da761116e22

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2025-07-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CERT-UA warns of LameHug, a novel Python-based Windows infostealer attributed with moderate confidence to Russia-linked APT28; it abuses an open-source LLM (Qwen 2.5-Coder-32B-Instruct) via HuggingFace to generate execution commands, collects system info and Office/PDF/TXT files from user folders, and exfiltrates data over SFTP or HTTP POST — delivered in a phishing campaign using a .zip containing a PyInstaller .pif payload and hosted on compromised legitimate services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.