TF-MAL-py.lamehug
📛 Threat Title
Malware family: LAMEHUG
Description
ThreatFox malware family `py.lamehug`. Printable name: LAMEHUG.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
py.lamehug
IOC database
- Type
- domain
- Value
py.lamehug- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-py.lamehug
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
A sophisticated new threat has emerged in the cybersecurity landscape that represents a significant evolution in malware development. The LAMEHUG malware family , first identified by CERT-UA in July 2025, marks a concerning advancement in cyber attack methodology by integrating artificial intelligence directly into its operational framework. Unlike traditional malware that relies on static, pre ...
-
web:dailysecurityreview.com
LameHug malware uses an AI language model to craft system commands on the fly, targeting Windows machines in attacks linked to Russian-backed APT28.
-
web:malpedia.caad.fkie.fraunhofer.de
According to CERT-UA, LAMEHUG uses an LLM (Qwen) to dynamically generate commands to gather basic information about a computer and recursively exfiltrate Office documents from a set of folders, to be uploaded either by SFTP or HTTP POST requests.
-
web:omarrao.substack.com
Researchers analyzed LAMEHUG , a new malware family that leverages LLMs to generate system commands dynamically during intrusions.
-
web:thehackernews.com
APT28 targets Ukrainian government officials with a phishing campaign delivering LAMEHUG malware , utilizing Alibaba Cloud's LLM for data harvesting.
-
web:www.bleepingcomputer.com
A novel malware family named LameHug is using a large language model (LLM) to generate commands to be executed on compromised Windows systems.
-
web:www.catonetworks.com
LAMEHUG is an LLM-powered malware discovered by the Computer Emergency Response Team of Ukraine (CERT-UA). According to CERT-UA, LAMEHUG has links to APT28 (Fancy Bear).
-
web:www.cloudtango.net
How LameHug Uses AI in the Attack Chain What sets LameHug apart is its use of the Qwen 2.5-Coder-32B-Instruct model, an open-source LLM created by Alibaba Cloud and hosted via Hugging Face's API. This AI model, typically designed for code generation and reasoning, is leveraged by the malware to dynamically create shell commands based on prompts.
-
web:www.publicnow.com
From Prompt to Payload: LAMEHUG's LLM-Driven Cyber Intrusion Last July 2025, CERT-UA identified a new and unusually sophisticated threat: LAMEHUG , a malware family that uniquely integrates artificial intelligence into its attack workflow. Unlike traditional malware , LAMEHUG leverages large language models (LLMs) hosted on Hugging Face to dynamically generate commands for reconnaissance, data ...
-
web:www.splunk.com
Last July 2025, CERT-UA identified a new and unusually sophisticated threat: LAMEHUG , a malware family that uniquely integrates artificial intelligence into its attack workflow. Unlike traditional malware , LAMEHUG leverages large language models (LLMs) hosted on Hugging Face to dynamically generate commands for reconnaissance, data theft, and system manipulation in real time. Delivered via ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.