ATT&CKReferencesNov AI Threat Tracker

Nov AI Threat Tracker

Google Threat Intelligence Group. (2025, November 5). GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools. Retrieved March 31, 2026.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareLAMEHUG

LAMEHUG has the ability to collect system information and files of interest from compromised systems.

T1007
System Service Discovery
MalwareLAMEHUG

LAMEHUG can gather service information on targeted systems.

T1016
System Network Configuration Discovery
MalwareLAMEHUG

LAMEHUG can enumerate network information on compromised hosts.

T1036.005
Match Legitimate Resource Name or Location
MalwareLAMEHUG

LAMEHUG payloads have been disguised with legitimate looking filenames including AI_generator_uncensored_Canvas_PRO_v0.9.exe and AI_image_generator_v0.95.exe.

T1041
Exfiltration Over C2 Channel
MalwareLAMEHUG

LAMEHUG can exfiltrate collected system information and documents to C2.

T1057
Process Discovery
MalwareLAMEHUG

LAMEHUG can gather process information on targeted systems.

T1059.006
Python
MalwareLAMEHUG

LAMEHUG can use Python scripts for execution.

T1074.001
Local Data Staging
MalwareLAMEHUG

LAMEHUG can save collected data and files of interest in `C:\ProgramData\info\` to consolidate for exfiltration.

T1082
System Information Discovery
MalwareLAMEHUG

LAMEHUG has the ability to execute Windows commands returned from C2 to gather system information.

T1083
File and Directory Discovery
MalwareLAMEHUG

LAMEHUG can target directories on victim machines for file collection.

T1102.002
Bidirectional Communication
MalwareLAMEHUG

LAMEHUG has used the Hugging Face API to query the Qwen2.5-Coder-32B-Instruct LLM to generate one-line Windows commands for the collection of system information and documents in specific folders on compromised hosts. LAMEHUG subsequently executed the returned commands and exfiltrated the collected files and information to adversary-controlled C2 servers.

T1119
Automated Collection
MalwareLAMEHUG

LAMEHUG can recursively copy files from targeted directories on victim hosts.

T1482
Domain Trust Discovery
MalwareLAMEHUG

LAMEHUG can gather Active Directory domain information.

T1588.007
Artificial Intelligence
GroupAPT28

APT28 has deployed LAMEHUG which can can query an LLM to generate and return commands for post compromise activity on targeted systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.