Malware
LAMEHUG
According to CERT-UA, LAMEHUG uses an LLM (Qwen) to dynamically generate commands to gather basic information about a computer and recursively exfiltrate Office documents from a set of folders, to be
LAMEHUG is a Python malware family operated by APT28.
Background
CERT-UA reports that LAMEHUG taps an LLM (Qwen) to generate commands on the fly, both to collect basic details about a computer and to recursively pull Office documents from a defined set of folders, exfiltrating them over SFTP or via HTTP POST requests.
Source: Malpedia (Fraunhofer FKIE).