Simonovich, V. (2025, July 23). Cato CTRL™ Threat Research: Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 (Fancy Bear) . Retrieved April 21, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareLAMEHUG | LAMEHUG can gather service information on targeted systems. |
| T1057 Process Discovery |
MalwareLAMEHUG | LAMEHUG can gather process information on targeted systems. |
| T1069.002 Domain Groups |
MalwareLAMEHUG | |
| T1087.002 Domain Account |
MalwareLAMEHUG | LAMEHUG can use dsquery to enumerate domain user information. |
| T1204.002 Malicious File |
GroupAPT28 | APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts. |
| T1566.001 Spearphishing Attachment |
GroupAPT28 | APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments. |
| T1684.001 Impersonation |
GroupAPT28 | LAMEHUG has sent spearphishing emails impersonating Ukrainian government officials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.