logo

LameHug: The First Publicly Documented Case of a Malware Integrating a LLM

ID: 1c5f6932-7749-5017-8396-c7e3a2f9bccb

STIX ID: report--1c5f6932-7749-5017-8396-c7e3a2f9bccb

Feed Name: Resources-2

Threat Score
90/100

Date Published: 2025-08-11

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren Hacıoğlu)

...
...

**Executive Summary:** LameHug is a Python-based infostealer attributed to APT28 that uses a cloud-hosted LLM (Alibaba Qwen via Hugging Face) to generate adaptive Windows command chains at runtime for rapid reconnaissance and exfiltration; delivered through spear-phishing ZIP/PIF attachments, it stages data to %ProgramData%\info and exfiltrates via SFTP or HTTP, representing a significant advancement in AI-assisted malware tradecraft and posing a high espionage risk to targeted government networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.