ATT&CKReferencesCato LAMEHUG JUL 2025

Cato LAMEHUG JUL 2025

Simonovich, V. (2025, July 23). Cato CTRL™ Threat Research: Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 (Fancy Bear) . Retrieved April 21, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareLAMEHUG

LAMEHUG can gather service information on targeted systems.

T1057
Process Discovery
MalwareLAMEHUG

LAMEHUG can gather process information on targeted systems.

T1069.002
Domain Groups
MalwareLAMEHUG

LAMEHUG can use dsquery to gather domain group information.

T1087.002
Domain Account
MalwareLAMEHUG

LAMEHUG can use dsquery to enumerate domain user information.

T1204.002
Malicious File
GroupAPT28

APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts.

T1566.001
Spearphishing Attachment
GroupAPT28

APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments.

T1684.001
Impersonation
GroupAPT28

LAMEHUG has sent spearphishing emails impersonating Ukrainian government officials.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.