ATT&CKReferencesSplunk LAMEHUG SEP 2025

Splunk LAMEHUG SEP 2025

Conteras, T., Splunk Research Team. (2025, September 25). From Prompt to Payload: LAMEHUG’s LLM-Driven Cyber Intrusion. Retrieved April 21, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareLAMEHUG

LAMEHUG has the ability to collect system information and files of interest from compromised systems.

T1033
System Owner/User Discovery
MalwareLAMEHUG

LAMEHUG can use `whoami` to enumerate the system user.

T1036.005
Match Legitimate Resource Name or Location
MalwareLAMEHUG

LAMEHUG payloads have been disguised with legitimate looking filenames including AI_generator_uncensored_Canvas_PRO_v0.9.exe and AI_image_generator_v0.95.exe.

T1041
Exfiltration Over C2 Channel
MalwareLAMEHUG

LAMEHUG can exfiltrate collected system information and documents to C2.

T1047
Windows Management Instrumentation
MalwareLAMEHUG

LAMEHUG can use wmic to collect system information.

T1059.003
Windows Command Shell
MalwareLAMEHUG

LAMEHUG can use `cmd.exe` to display a decoy file to spearphishing victims.

T1059.006
Python
MalwareLAMEHUG

LAMEHUG can use Python scripts for execution.

T1071.001
Web Protocols
MalwareLAMEHUG

LAMEHUG can use HTTP POST requests to exfiltrate data from compromised hosts to C2.

T1074.001
Local Data Staging
MalwareLAMEHUG

LAMEHUG can save collected data and files of interest in `C:\ProgramData\info\` to consolidate for exfiltration.

T1082
System Information Discovery
MalwareLAMEHUG

LAMEHUG has the ability to execute Windows commands returned from C2 to gather system information.

T1083
File and Directory Discovery
MalwareLAMEHUG

LAMEHUG can target directories on victim machines for file collection.

T1102.002
Bidirectional Communication
MalwareLAMEHUG

LAMEHUG has used the Hugging Face API to query the Qwen2.5-Coder-32B-Instruct LLM to generate one-line Windows commands for the collection of system information and documents in specific folders on compromised hosts. LAMEHUG subsequently executed the returned commands and exfiltrated the collected files and information to adversary-controlled C2 servers.

T1119
Automated Collection
MalwareLAMEHUG

LAMEHUG can recursively copy files from targeted directories on victim hosts.

T1132
Data Encoding
MalwareLAMEHUG

LAMEHUG can encode queries sent to LLMs.

T1140
Deobfuscate/Decode Files or Information
MalwareLAMEHUG

LAMEHUG can decode and drop a decoy file attached to spearphishing emails.

T1204.002
Malicious File
MalwareLAMEHUG

LAMEHUG has been executed through victim interaction with malicious email attachments made to look like legitimate AI applications or documents.

T1560.001
Archive via Utility
MalwareLAMEHUG

LAMEHUG can xcopy for file collection on targeted systems.

T1566.001
Spearphishing Attachment
MalwareLAMEHUG

LAMEHUG has been distributed through spearphishing emails with various AI-themed malicious attachments.

T1573.002
Asymmetric Cryptography
MalwareLAMEHUG

LAMEHUG can use SSH to transfer information to C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.