Malware.View on attack.mitre.org
LAMEHUG is Python-based information stealer first identified in July 2025 by Ukraine's Computer Emergency Response Team (CERT-UA) in phishing emails targeting Ukrainian government officials. LAMEHUG is the first known malware to integrate artificial intelligence (AI) directly into its attack workflow by querying large language models (LLMs) hosted on Hugging Face to dynamically generate reconnaissance, data theft, and system manipulation commands in real time. LAMEHUG has been attributed to APT28.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
LAMEHUG has the ability to collect system information and files of interest from compromised systems. |
| T1007 System Service Discovery |
LAMEHUG can gather service information on targeted systems. |
| T1016 System Network Configuration Discovery |
LAMEHUG can enumerate network information on compromised hosts. |
| T1033 System Owner/User Discovery |
LAMEHUG can use `whoami` to enumerate the system user. |
| T1036.005 Match Legitimate Resource Name or Location |
LAMEHUG payloads have been disguised with legitimate looking filenames including AI_generator_uncensored_Canvas_PRO_v0.9.exe and AI_image_generator_v0.95.exe. |
| T1041 Exfiltration Over C2 Channel |
LAMEHUG can exfiltrate collected system information and documents to C2. |
| T1047 Windows Management Instrumentation |
LAMEHUG can use wmic to collect system information. |
| T1057 Process Discovery |
LAMEHUG can gather process information on targeted systems. |
| T1059.003 Windows Command Shell |
LAMEHUG can use `cmd.exe` to display a decoy file to spearphishing victims. |
| T1059.006 Python |
LAMEHUG can use Python scripts for execution. |
| T1069.002 Domain Groups |
|
| T1071.001 Web Protocols |
LAMEHUG can use HTTP POST requests to exfiltrate data from compromised hosts to C2. |
| T1074.001 Local Data Staging |
LAMEHUG can save collected data and files of interest in `C:\ProgramData\info\` to consolidate for exfiltration. |
| T1082 System Information Discovery |
LAMEHUG has the ability to execute Windows commands returned from C2 to gather system information. |
| T1083 File and Directory Discovery |
LAMEHUG can target directories on victim machines for file collection. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.