Google Threat Intelligence Group. (2025, November 5). GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools. Retrieved March 31, 2026.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareLAMEHUG | LAMEHUG has the ability to collect system information and files of interest from compromised systems. |
| T1007 System Service Discovery |
MalwareLAMEHUG | LAMEHUG can gather service information on targeted systems. |
| T1016 System Network Configuration Discovery |
MalwareLAMEHUG | LAMEHUG can enumerate network information on compromised hosts. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLAMEHUG | LAMEHUG payloads have been disguised with legitimate looking filenames including AI_generator_uncensored_Canvas_PRO_v0.9.exe and AI_image_generator_v0.95.exe. |
| T1041 Exfiltration Over C2 Channel |
MalwareLAMEHUG | LAMEHUG can exfiltrate collected system information and documents to C2. |
| T1057 Process Discovery |
MalwareLAMEHUG | LAMEHUG can gather process information on targeted systems. |
| T1059.006 Python |
MalwareLAMEHUG | LAMEHUG can use Python scripts for execution. |
| T1074.001 Local Data Staging |
MalwareLAMEHUG | LAMEHUG can save collected data and files of interest in `C:\ProgramData\info\` to consolidate for exfiltration. |
| T1082 System Information Discovery |
MalwareLAMEHUG | LAMEHUG has the ability to execute Windows commands returned from C2 to gather system information. |
| T1083 File and Directory Discovery |
MalwareLAMEHUG | LAMEHUG can target directories on victim machines for file collection. |
| T1102.002 Bidirectional Communication |
MalwareLAMEHUG | LAMEHUG has used the Hugging Face API to query the Qwen2.5-Coder-32B-Instruct LLM to generate one-line Windows commands for the collection of system information and documents in specific folders on compromised hosts. LAMEHUG subsequently executed the returned commands and exfiltrated the collected files and information to adversary-controlled C2 servers. |
| T1119 Automated Collection |
MalwareLAMEHUG | LAMEHUG can recursively copy files from targeted directories on victim hosts. |
| T1482 Domain Trust Discovery |
MalwareLAMEHUG | LAMEHUG can gather Active Directory domain information. |
| T1588.007 Artificial Intelligence |
GroupAPT28 | APT28 has deployed LAMEHUG which can can query an LLM to generate and return commands for post compromise activity on targeted systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.