logo

What Is LameHug? How APT28 is using LLMs to generate attack commands

ID: e1a5c374-5f1f-56f6-b3bc-dcdcd7b36a55

STIX ID: report--e1a5c374-5f1f-56f6-b3bc-dcdcd7b36a55

Feed Name: ThreatLocker Blog

Threat Score
85/100

Date Published: 2025-08-12

Date Updated: 2026-05-01

...
...

LameHug is a Python-based information stealer identified by CERT‑UA that uniquely leverages an LLM (Qwen 2.5-Coder-32B-Instruct) to dynamically generate data-extraction commands; ThreatLocker’s analysis ties the malware to APT28 (Fancy Bear), details technical differences between versions, provides multiple SHA256 hashes, domains and IPs as IOCs, and recommends mitigations such as application allowlisting, ringfencing, storage control, and EDR detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.