s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-py.lamehug

📛 Threat Title

Malware family: LAMEHUG

Category: LAMEHUG First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.lamehug`. Printable name: LAMEHUG.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain py.lamehug

IOC database

Type
domain
Value
py.lamehug
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-py.lamehug

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

Remediations (10)

  • web:cybersecuritynews.com

    A sophisticated new threat has emerged in the cybersecurity landscape that represents a significant evolution in malware development. The LAMEHUG malware family , first identified by CERT-UA in July 2025, marks a concerning advancement in cyber attack methodology by integrating artificial intelligence directly into its operational framework. Unlike traditional malware that relies on static, pre ...

  • web:dailysecurityreview.com

    LameHug malware uses an AI language model to craft system commands on the fly, targeting Windows machines in attacks linked to Russian-backed APT28.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to CERT-UA, LAMEHUG uses an LLM (Qwen) to dynamically generate commands to gather basic information about a computer and recursively exfiltrate Office documents from a set of folders, to be uploaded either by SFTP or HTTP POST requests.

  • web:omarrao.substack.com

    Researchers analyzed LAMEHUG , a new malware family that leverages LLMs to generate system commands dynamically during intrusions.

  • web:thehackernews.com

    APT28 targets Ukrainian government officials with a phishing campaign delivering LAMEHUG malware , utilizing Alibaba Cloud's LLM for data harvesting.

  • web:www.bleepingcomputer.com

    A novel malware family named LameHug is using a large language model (LLM) to generate commands to be executed on compromised Windows systems.

  • web:www.catonetworks.com

    LAMEHUG is an LLM-powered malware discovered by the Computer Emergency Response Team of Ukraine (CERT-UA). According to CERT-UA, LAMEHUG has links to APT28 (Fancy Bear).

  • web:www.cloudtango.net

    How LameHug Uses AI in the Attack Chain What sets LameHug apart is its use of the Qwen 2.5-Coder-32B-Instruct model, an open-source LLM created by Alibaba Cloud and hosted via Hugging Face's API. This AI model, typically designed for code generation and reasoning, is leveraged by the malware to dynamically create shell commands based on prompts.

  • web:www.publicnow.com

    From Prompt to Payload: LAMEHUG's LLM-Driven Cyber Intrusion Last July 2025, CERT-UA identified a new and unusually sophisticated threat: LAMEHUG , a malware family that uniquely integrates artificial intelligence into its attack workflow. Unlike traditional malware , LAMEHUG leverages large language models (LLMs) hosted on Hugging Face to dynamically generate commands for reconnaissance, data ...

  • web:www.splunk.com

    Last July 2025, CERT-UA identified a new and unusually sophisticated threat: LAMEHUG , a malware family that uniquely integrates artificial intelligence into its attack workflow. Unlike traditional malware , LAMEHUG leverages large language models (LLMs) hosted on Hugging Face to dynamically generate commands for reconnaissance, data theft, and system manipulation in real time. Delivered via ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.