Thursday 18 June, 2026
[email protected]
Resilience Media
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • About
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • About
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

Ukraine warns of AI-powered malware targeting the defence sector

CERT-UA says LAMEHUG malware uses an LLM model to craft commands in real-time and evade detection.

Resilience MediabyResilience Media
August 3, 2025
in News
Photo by charlesdeluvio on Unsplash

Photo by charlesdeluvio on Unsplash

Share on Linkedin

Ukraine’s national cyber authority has issued a warning about what it says is the first known use of large language model-powered malware in active attacks targeting the country’s defence and security sector.

You Might Also Like

The Next Defence Primes: Kela, Dominion Dynamics and Terra Leaders Join Resilience Conference London

How NATO’s Eastern Flank Deterrence Initiative is turning rhetoric into real capability

Comand AI raises €32M for its C2 software, adds Saab as a strategic backer

According to CERT-UA, Ukraine’s Computer Emergency Response Team, the so-called “LAMEHUG” malware was deployed in a recent campaign that it first uncovered on 10 July. The agency says it assesses, with moderate confidence, that the attacks are the work of APT28, a state-sponsored hacking group aligned with Russia’s military intelligence agency, the GRU.

APT28, also known as UAC-0001 and Fancy Bear, has been linked to several high-profile espionage and sabotage operations around the world, including a string of attacks on UK defence organisations involved in delivering foreign assistance to Ukraine.

Earlier this month, the UK’s National Cyber Security Centre also formally linked Fancy Bear to a cyber campaign targeting Western logistics and technology sectors using the ‘Authentic Antics’ malware, and sanctioned 18 Russian individuals connected to the attacks.

In the Russia-backed group’s latest campaign observed by CERT-UA, the LAMEHUG malware is delivered through phishing emails disguised as communications from Ukrainian ministries. Once opened, a malicious .pif file triggers the LAMEHUG loader, which then connects to an open-source LLM hosted on Hugging Face’s cloud platform. Using Qwen 2.5-Coder-32B-Instruct, a powerful AI model capable of generating code and commands, to dynamically generate commands.

Unlike traditional malware that relies on pre-programmed instructions, LAMEHUG uses the LLM to gather detailed information about the victim’s computer, including hardware specifications, running processes, and network configurations. It then scans for sensitive documents, such as PDFs, Word files, and spreadsheets, before exfiltrating data via encrypted channels.

What makes LAMEHUG particularly dangerous is its stealth and flexibility. Because the malware is generating commands via a public API, its traffic can be hard to distinguish from legitimate AI use within an organisation. This means traditional antivirus tools and endpoint detection platforms may miss it entirely.

Vitaly Simonovich, a threat intelligence researcher at Cato Networks, warns that this marks a turning point in the evolution of cyber threats, where attackers use off-the-shelf generative AI tools to automate reconnaissance, tailor commands, and potentially adapt in real time without further human intervention.

“The discovery of LAMEHUG by CERT-UA marks a significant milestone in the threat landscape,” he told Resilience Media. “The campaign highlights state-sponsored investment in emerging AI technologies for cyber activities, with Ukraine serving as the testing ground for these new capabilities. The relatively simple implementation suggests this is APT28’s attempt at learning how to weaponise LLMs, likely opening the door for more sophisticated AI-driven campaigns in the future.”

This incident also highlights growing concerns about how open-source AI models, often released with minimal restrictions, could be weaponised. While the AI community continues to debate safety and governance, LAMEHUG may prove to be the first real-world case of an LLM being actively used in a hostile cyber campaign with zero human intervention.

CERT-UA did not specify if LAMEHUG’s execution of the LLM-generated commands was successful, what agencies were targeted, or whether any sensitive data was accessed.

Tags: NCSCUkraineVitaly Simonovich
Previous Post

Deep tech breakthroughs in Ukraine get a boost from Europe

Next Post

Resilience Media Secures Investment, Scales its Editorial Team

Resilience Media

Resilience Media

Start Ups. Security. Defense.

Related News

Iceye, the Finnish satellite startup, nabs €1B at a €10B valuation amid growing demand for space intel

The Next Defence Primes: Kela, Dominion Dynamics and Terra Leaders Join Resilience Conference London

byLeslie Hitchcock
June 18, 2026

Who will build the next defence primes? The defence industrial base is undergoing a once-in-a-generation transformation. A new cohort of...

A man with a gun standing in the woods

How NATO’s Eastern Flank Deterrence Initiative is turning rhetoric into real capability

byArnel P. Davidand1 others
June 17, 2026

"Innovation" has become one of the most casually abused terms in defence circles. It appears in speeches, strategies, and budget...

Comand AI raises €32M for its C2 software, adds Saab as a strategic backer

Comand AI raises €32M for its C2 software, adds Saab as a strategic backer

byIngrid Lunden
June 17, 2026

Europe is betting big on artificial intelligence playing a significant role in how defence will be planned and executed in...

white red and green map

BAE puts €50M into Lakestar and Expeditions to back defence tech startups

byIngrid Lunden
June 17, 2026

As the UK defence sector braces for the publication of the Defence Investment Plan, the country's biggest defence prime is...

Lithuania’s PDKinematics raises €2M to scale precision guidance systems across NATO

Lithuania’s PDKinematics raises €2M to scale precision guidance systems across NATO

byFiona Alston
June 17, 2026

Lithuanian startup PDKinematics has raised a €2 million seed round to help the company scale manufacturing as it targets NATO...

Can AI save a satellite before it fails? PiLogic thinks so

Can AI save a satellite before it fails? PiLogic thinks so

byJohn Biggs
June 16, 2026

https://youtu.be/xSj3z-7nzqA Artificial intelligence is rapidly finding its way into defence and aerospace systems, but many of today's AI tools come...

Alpine Eagle and Origin Robotics integrate to strengthen counter-drone defence

Alpine Eagle and Origin Robotics integrate to strengthen counter-drone defence

byFiona Alstonand1 others
June 16, 2026

German counter-drone defence technology company Alpine Eagle and Latvian autonomous systems startup Origin Robotics have signed an integration memorandum of...

In Kyiv, naval drone developers look beyond the kamikaze era

In Kyiv, naval drone developers look beyond the kamikaze era

byLuke Smith
June 16, 2026

Ukraine has made effective use of sea drones, surface vessels and other new technology to take on Russia's traditional naval...

Load More
Next Post
Welcome to Resilience Media

Resilience Media Secures Investment, Scales its Editorial Team

SEB Expands Defence-Sector Investment Access, Launches Thematic Fund for Europe’s Strategic Resilience

SEB Expands Defence-Sector Investment Access, Launches Thematic Fund for Europe’s Strategic Resilience

Most viewed

InVeris announces fats Drone, an integrated, multi-party drone flight simulator

Uforce raises $50M at a $1B+ valuation to build defence tech for Ukraine

Auterion, the drone software startup, eyes raising $200M at a $1.2B+ valuation

Palantir and Ukraine’s Brave1 have built a new AI “Dataroom”

Twentyfour Industries emerges from stealth with $11.8M for mass-produced drones

Senai exits stealth to help governments harness online video intelligence

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions
  • Mission Statement & Code of Practice
  • Press

© 2026 Resilience Media

No Result
View All Result
  • Home
  • About
  • Subscribe
  • Events
  • Guest Posts
  • Interview
  • News
  • Resilience Conference London 2026
  • Resilience Conference Copenhagen 2026
  • Resilience Conference Warsaw 2026

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.