Thursday 17 September, 2026
[email protected]
Resilience Media
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference London — Oct 2026
    • Resilience Conference Copenhagen — May 2026 (PAST)
    • Resilience Conference Warsaw — Apr 2026 (PAST)
  • Launch
  • About
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference London — Oct 2026
    • Resilience Conference Copenhagen — May 2026 (PAST)
    • Resilience Conference Warsaw — Apr 2026 (PAST)
  • Launch
  • About
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

Ukraine warns of AI-powered malware targeting the defence sector

CERT-UA says LAMEHUG malware uses an LLM model to craft commands in real-time and evade detection.

Resilience MediabyResilience Media
August 3, 2025
in News
Photo by charlesdeluvio on Unsplash

Photo by charlesdeluvio on Unsplash

Share on Linkedin

Ukraine’s national cyber authority has issued a warning about what it says is the first known use of large language model-powered malware in active attacks targeting the country’s defence and security sector.

You Might Also Like

The London Defence Tech Week programme is here

Canada’s SPARC AI launches GPS-free positioning for soldiers

Martin Herem appointed Estonia’s new defence minister

According to CERT-UA, Ukraine’s Computer Emergency Response Team, the so-called “LAMEHUG” malware was deployed in a recent campaign that it first uncovered on 10 July. The agency says it assesses, with moderate confidence, that the attacks are the work of APT28, a state-sponsored hacking group aligned with Russia’s military intelligence agency, the GRU.

APT28, also known as UAC-0001 and Fancy Bear, has been linked to several high-profile espionage and sabotage operations around the world, including a string of attacks on UK defence organisations involved in delivering foreign assistance to Ukraine.

Earlier this month, the UK’s National Cyber Security Centre also formally linked Fancy Bear to a cyber campaign targeting Western logistics and technology sectors using the ‘Authentic Antics’ malware, and sanctioned 18 Russian individuals connected to the attacks.

In the Russia-backed group’s latest campaign observed by CERT-UA, the LAMEHUG malware is delivered through phishing emails disguised as communications from Ukrainian ministries. Once opened, a malicious .pif file triggers the LAMEHUG loader, which then connects to an open-source LLM hosted on Hugging Face’s cloud platform. Using Qwen 2.5-Coder-32B-Instruct, a powerful AI model capable of generating code and commands, to dynamically generate commands.

Unlike traditional malware that relies on pre-programmed instructions, LAMEHUG uses the LLM to gather detailed information about the victim’s computer, including hardware specifications, running processes, and network configurations. It then scans for sensitive documents, such as PDFs, Word files, and spreadsheets, before exfiltrating data via encrypted channels.

What makes LAMEHUG particularly dangerous is its stealth and flexibility. Because the malware is generating commands via a public API, its traffic can be hard to distinguish from legitimate AI use within an organisation. This means traditional antivirus tools and endpoint detection platforms may miss it entirely.

Vitaly Simonovich, a threat intelligence researcher at Cato Networks, warns that this marks a turning point in the evolution of cyber threats, where attackers use off-the-shelf generative AI tools to automate reconnaissance, tailor commands, and potentially adapt in real time without further human intervention.

“The discovery of LAMEHUG by CERT-UA marks a significant milestone in the threat landscape,” he told Resilience Media. “The campaign highlights state-sponsored investment in emerging AI technologies for cyber activities, with Ukraine serving as the testing ground for these new capabilities. The relatively simple implementation suggests this is APT28’s attempt at learning how to weaponise LLMs, likely opening the door for more sophisticated AI-driven campaigns in the future.”

This incident also highlights growing concerns about how open-source AI models, often released with minimal restrictions, could be weaponised. While the AI community continues to debate safety and governance, LAMEHUG may prove to be the first real-world case of an LLM being actively used in a hostile cyber campaign with zero human intervention.

CERT-UA did not specify if LAMEHUG’s execution of the LLM-generated commands was successful, what agencies were targeted, or whether any sensitive data was accessed.

Tags: NCSCUkraineVitaly Simonovich
Previous Post

Deep tech breakthroughs in Ukraine get a boost from Europe

Next Post

Resilience Media Secures Investment, Scales its Editorial Team

Resilience Media

Resilience Media

Start Ups. Security. Defense.

Related News

The London Defence Tech Week programme is here

The London Defence Tech Week programme is here

byLeslie Hitchcock
September 17, 2026

From 1-8 October, London Defence Tech Week brings together conferences, networking events, workshops, investor gatherings and partner events across London....

Canada’s SPARC AI launches GPS-free positioning for soldiers

Canada’s SPARC AI launches GPS-free positioning for soldiers

byJohn Biggs
September 16, 2026

Canadian defense technology company SPARC AI has launched Overwatch Patrol, a positioning system designed to let soldiers track themselves and...

Martin Herem appointed Estonia’s new defence minister

Martin Herem appointed Estonia’s new defence minister

byIngrid Lunden
September 16, 2026

Two weeks after losing its defence minister amid a botched Ukraine procurement deal, Estonia has named a new person from...

‘We’ve had the proliferation phase in Ukraine, now we go into consolidation’

‘We’ve had the proliferation phase in Ukraine, now we go into consolidation’

byLuke Smith
September 16, 2026

When the MITS Lightning Fund closed its first venture fund in May, its partners had raised slightly more than $20...

Exein raises $270M to build embedded cybersecurity for physical AI systems

Exein raises $270M to build embedded cybersecurity for physical AI systems

byIngrid Lunden
September 15, 2026

AI is powering an increasing array of hardware today, from robots and autonomous vehicles to drones and your phone. That...

Open Cosmos fires up its satellite ambitions with €300M

Open Cosmos fires up its satellite ambitions with €300M

byIngrid Lunden
September 14, 2026

Open Cosmos, a UK startup founded by three engineers from Spain, made a name for itself in 2015 when it...

Isembard puts critical manufacturing minutes from Whitehall

Isembard puts critical manufacturing minutes from Whitehall

byCarly Page
September 14, 2026

British manufacturing startup Isembard has opened a 160,000 square-feet factory in central London that will produce components for defence, aerospace...

Finland’s Creoir gets backing from Gungnir Capital for its on-device speech tech

Finland’s Creoir gets backing from Gungnir Capital for its on-device speech tech

byFiona Alston
September 14, 2026

Finland's Creoir, a developer of voice interface technology, has raised investment from Swedish VC Gungnir Capital. The funding is part...

Load More
Next Post
Welcome to Resilience Media

Resilience Media Secures Investment, Scales its Editorial Team

SEB Expands Defence-Sector Investment Access, Launches Thematic Fund for Europe’s Strategic Resilience

SEB Expands Defence-Sector Investment Access, Launches Thematic Fund for Europe’s Strategic Resilience

Top stories

Something new, something BIG at Resilience Conference London
News

Meet the LAUNCH@RC and SCALE@RC 2026 Cohorts

September 11, 2026
Exein raises $270M to build embedded cybersecurity for physical AI systems
Cyber

Exein raises $270M to build embedded cybersecurity for physical AI systems

September 15, 2026
Website interface with text and abstract drawing
News

Claude AI helped Russia-based threat actors develop autonomous kamikaze drone swarm

September 11, 2026
Isembard puts critical manufacturing minutes from Whitehall
News

Isembard puts critical manufacturing minutes from Whitehall

September 14, 2026

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions
  • Mission Statement & Code of Practice
  • Press

© 2026 Resilience Media

No Result
View All Result
  • Home
  • About
  • Subscribe
  • Events
  • Guest Posts
  • Interview
  • News
  • Resilience Conference London 2026
  • Resilience Conference Copenhagen 2026
  • Resilience Conference Warsaw 2026

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.