Skip to content

Malware

LAMEHUG

According to CERT-UA, LAMEHUG uses an LLM (Qwen) to dynamically generate commands to gather basic information about a computer and recursively exfiltrate Office documents from a set of folders, to be

LAMEHUG is a Python malware family operated by APT28.

Background

CERT-UA reports that LAMEHUG taps an LLM (Qwen) to generate commands on the fly, both to collect basic details about a computer and to recursively pull Office documents from a defined set of folders, exfiltrating them over SFTP or via HTTP POST requests.


Source: Malpedia (Fraunhofer FKIE).