LAMEHUG, also known as PROMPTSTEAL, is a Python-based, AI-assisted information stealer targeting Windows systems. It queries a Hugging Face-hosted Qwen coding model at runtime to generate environment-specific Windows commands for host reconnaissance and collection of documents and other data. This approach reduces reliance on static command sequences and can yield different collection commands across victim environments. CERT-UA reported LAMEHUG in July 2025 in attacks against Ukrainian government entities and attributed the activity with medium confidence to APT28/UAC-0001, a Russia-linked espionage actor. Reported delivery involved spearphishing emails impersonating Ukrainian government officials.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...a prominent public example is LAMEHUG, which CERT-UA attributed with medium confidence to APT28/UAC-0001 (IRON TWILIGHT) and described as using Qwen2.5-Coder-32B-Instruct via Hugging Face to generate commands at runtime.
„PROMPTSTEAL ist demnach die erste in freier Wildbahn beobachtete Malware, die LLMs abfragt… Um Befehle zu generieren, verwende dieser Data Miner die Hugging Face API…“
34 distinct techniques documented for this family, organized by ATT&CK tactic.
“PROMPTSTEAL can use a model to create single-line Windows commands for document collection.”
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
87 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously reported malware example that used an AI model to generate commands for predefined tasks. It is cited as a comparison to CLOSEDQUORUM's AI-driven task-selection mechanism.
Malware reported in 2025 that used Alibaba's Qwen model, via Hugging Face, to generate commands during attacks.
Described as the earliest known malware sample integrating AI functionality.
Identified as one of the first AI-integrated malware samples reported in the wild.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.