Cato CTRL™ Threat Research: Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 (Fancy Bear)
ID: d31255a0-c69f-5490-bb09-c30524138c31
STIX ID: report--d31255a0-c69f-5490-bb09-c30524138c31
Feed Name: Cato Networks
**Executive Summary:** On July 17, 2025 CERT-UA disclosed the LAMEHUG campaign—malware that integrates an LLM (Qwen2.5-Coder-32B-Instruct via Hugging Face APIs) to generate and execute reconnaissance and data‑collection commands in real time—attributed with moderate confidence to APT28 and delivered via phishing ZIP attachments to Ukrainian government officials; multiple variants perform document harvesting and exfiltration over SFTP or HTTP and the report includes prompts, generated command sequences, file hashes, IPs and domains as IoCs, while assessing the activity as likely PoC testing and recommending AI‑access controls and network/endpoint defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
