Malware

LAMEHUG

According to CERT-UA, LAMEHUG uses an LLM (Qwen) to dynamically generate commands to gather basic information about a computer and recursively exfiltrate Office documents from a set of folders, to be uploaded either by SFTP or HTTP POST requests.

Indicators of Compromise 8

MITRE ATT&CK TTPs 8

Source Articles