LAMEHUG, also referred to as PROMPTSTEAL, is a Windows infostealer notable for integrating a live large language model into its runtime workflow. The malware queries a Hugging Face-hosted coding model to generate host-specific Windows commands on demand, then executes those commands to perform reconnaissance and collect documents and other information of interest. Reported command generation has included system and user discovery as well as recursive collection of files from targeted directories, with stolen data staged locally before exfiltration.
The malware has been associated with spearphishing campaigns targeting Ukrainian government and security or defense entities, including lures impersonating Ukrainian government officials and decoy content presented to victims. Observed variants have masqueraded as benign software or opened decoy documents while a malicious thread handled command generation, collection, and theft in the background.
LAMEHUG has been publicly linked with moderate confidence to APT28, also tracked as UAC-0001, a Russia-aligned espionage actor. It has been described as one of the earliest publicly documented examples of LLM-assisted malware in active operations. Its use of a remote model to produce different commands per environment reduces reliance on static embedded logic and can complicate traditional static analysis. Primary observed objectives have been reconnaissance, document collection, and exfiltration from compromised Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...a prominent public example is LAMEHUG, which CERT-UA attributed with medium confidence to APT28/UAC-0001 (IRON TWILIGHT) and described as using Qwen2.5-Coder-32B-Instruct via Hugging Face to generate commands at runtime.
„PROMPTSTEAL ist demnach die erste in freier Wildbahn beobachtete Malware, die LLMs abfragt… Um Befehle zu generieren, verwende dieser Data Miner die Hugging Face API…“
23 distinct techniques documented for this family, organized by ATT&CK tactic.
There were no new MITRE attack techniques. Seven of eight operations ran T1059, Command & Scripting Interpreter, the single most ordinary technique in the framework.
The following analytic detects the enumeration of Windows services using the net start command, which is a built-in utility that lists all running services on a system.
Kimsuky used malicious LNK files, the Dropbox API, GitHub Releases, and Google Drive for Information Theft and command execution.
The dynamically generated commands enable the malware to gather system information and identify sensitive files before transmitting them across the network to an adversary-controlled server.
The content repeatedly describes threat actors, malware, and campaigns using HTTP, HTTPS, HTTP GET/POST, cookies in headers, WebSockets/WSS, and web APIs for command and control or related communications.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
79 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family described as using live LLM interaction to generate system commands on demand, adapting commands to the victim environment.
A malware example cited for using an LLM at runtime to generate commands.
Data-mining malware that contacts a live LLM to generate host-specific command chains during execution.
Described as the first known LLM-powered malware, linked to APT28/Fancy Bear and used against security and defense sector targets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.