LameHug, also referred to as PROMPTSTEAL, is a Windows-focused AI-assisted infostealer associated with APT28, also known as Fancy Bear or UAC-0001, and used in espionage activity against Ukrainian government and defense-related targets. It is notable for delegating part of its operational logic to a large language model at runtime, querying a Hugging Face-hosted Qwen 2.5-Coder model to generate Windows shell commands dynamically rather than relying solely on hard-coded command sequences. This approach enables environment-specific reconnaissance and document collection while reducing the value of static analysis.
Observed LameHug activity includes host and system discovery, service enumeration, collection of documents from selected directories, local staging of gathered data, and exfiltration to attacker-controlled infrastructure. Reported command generation has covered system and user identification, hardware and operating system profiling, and recursive copying of files of interest for later theft. Some variants consolidated collected information in a staging directory before transfer, and exfiltration has been observed over both HTTPS and SSH-based channels.
Delivery has been linked to spearphishing campaigns, including emails impersonating Ukrainian government officials and lures masquerading as AI-related software or legitimate documents. Certain samples displayed decoy content to distract victims while a malicious thread performed reconnaissance and theft in the background. Public reporting describes the malware as Python-based in some cases, though multiple variants have been discussed.
LameHug is widely cited as one of the earliest real-world examples of malware using a live commercial or public LLM service to produce operational commands during an intrusion. Its use reflects APT28’s broader evolution toward disposable, specialized tooling, abuse of legitimate cloud services, and experimentation with AI to improve flexibility and stealth in cyber espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT28 evolved PixyNetLoader, utilizing COM persistence, PNG steganography, and FILEN-based cloud C2, and expanded its tactics to include X-Agent, X-Tunnel, and LameHug (malware that generates commands using an LLM and collects documents for Information Theft).
Known for blending cutting-edge tools such as the large language model (LLM) ‘LAMEHUG’ with proven, longstanding techniques, Forest Blizzard consistently evolves its tactics to stay ahead of defenders.
„PROMPTSTEAL ist demnach die erste in freier Wildbahn beobachtete Malware, die LLMs abfragt… Um Befehle zu generieren, verwende dieser Data Miner die Hugging Face API…“
24 distinct techniques documented for this family, organized by ATT&CK tactic.
AI-generated code: A threat actor uses a coding assistant, such as Cursor, to create scripts, exploits, payloads, and/or tools, which the human operator then deploys.
Both malware strains can "dynamically generate malicious scripts, obfuscate their own code to evade detection and leverage AI models to create malicious functions on demand," according to the report.
The following analytic detects the enumeration of Windows services using the net start command, which is a built-in utility that lists all running services on a system.
"data stolen: system inventories, network layouts, Active Directory hierarchies"
Kimsuky used malicious LNK files, the Dropbox API, GitHub Releases, and Google Drive for Information Theft and command execution.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
The dynamically generated commands enable the malware to gather system information and identify sensitive files before transmitting them across the network to an adversary-controlled server.
The content repeatedly describes threat actors, malware, and campaigns using HTTP, HTTPS, HTTP GET/POST, cookies in headers, WebSockets/WSS, and web APIs for command and control or related communications.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
74 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that generates commands using an LLM and collects documents for information theft.
LLM-assisted malware in which a human-defined workflow uses a public LLM to generate reconnaissance and data-theft commands on the fly, rather than autonomously operating end-to-end.
Python-based malware that dynamically queried an LLM to generate Windows reconnaissance and data-theft commands at runtime, varying commands by environment.
An AI-driven infostealer that queries a live AI model to generate attack commands dynamically.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.