Thursday 19 March, 2026
[email protected]
Resilience Media
  • About
  • News
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • About
  • News
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

Ukraine warns of AI-powered malware targeting the defence sector

CERT-UA says LAMEHUG malware uses an LLM model to craft commands in real-time and evade detection.

Resilience MediabyResilience Media
August 3, 2025
in News
Photo by charlesdeluvio on Unsplash

Photo by charlesdeluvio on Unsplash

Share on Linkedin

Ukraine’s national cyber authority has issued a warning about what it says is the first known use of large language model-powered malware in active attacks targeting the country’s defence and security sector.

You Might Also Like

The UK is setting up meetings between Gulf states and defence tech startups

Sille Pettai steps down from CEO role at SmartCap

100 Startups to Watch in 2026

According to CERT-UA, Ukraine’s Computer Emergency Response Team, the so-called “LAMEHUG” malware was deployed in a recent campaign that it first uncovered on 10 July. The agency says it assesses, with moderate confidence, that the attacks are the work of APT28, a state-sponsored hacking group aligned with Russia’s military intelligence agency, the GRU.

APT28, also known as UAC-0001 and Fancy Bear, has been linked to several high-profile espionage and sabotage operations around the world, including a string of attacks on UK defence organisations involved in delivering foreign assistance to Ukraine.

Earlier this month, the UK’s National Cyber Security Centre also formally linked Fancy Bear to a cyber campaign targeting Western logistics and technology sectors using the ‘Authentic Antics’ malware, and sanctioned 18 Russian individuals connected to the attacks.

In the Russia-backed group’s latest campaign observed by CERT-UA, the LAMEHUG malware is delivered through phishing emails disguised as communications from Ukrainian ministries. Once opened, a malicious .pif file triggers the LAMEHUG loader, which then connects to an open-source LLM hosted on Hugging Face’s cloud platform. Using Qwen 2.5-Coder-32B-Instruct, a powerful AI model capable of generating code and commands, to dynamically generate commands.

Unlike traditional malware that relies on pre-programmed instructions, LAMEHUG uses the LLM to gather detailed information about the victim’s computer, including hardware specifications, running processes, and network configurations. It then scans for sensitive documents, such as PDFs, Word files, and spreadsheets, before exfiltrating data via encrypted channels.

What makes LAMEHUG particularly dangerous is its stealth and flexibility. Because the malware is generating commands via a public API, its traffic can be hard to distinguish from legitimate AI use within an organisation. This means traditional antivirus tools and endpoint detection platforms may miss it entirely.

Vitaly Simonovich, a threat intelligence researcher at Cato Networks, warns that this marks a turning point in the evolution of cyber threats, where attackers use off-the-shelf generative AI tools to automate reconnaissance, tailor commands, and potentially adapt in real time without further human intervention.

“The discovery of LAMEHUG by CERT-UA marks a significant milestone in the threat landscape,” he told Resilience Media. “The campaign highlights state-sponsored investment in emerging AI technologies for cyber activities, with Ukraine serving as the testing ground for these new capabilities. The relatively simple implementation suggests this is APT28’s attempt at learning how to weaponise LLMs, likely opening the door for more sophisticated AI-driven campaigns in the future.”

This incident also highlights growing concerns about how open-source AI models, often released with minimal restrictions, could be weaponised. While the AI community continues to debate safety and governance, LAMEHUG may prove to be the first real-world case of an LLM being actively used in a hostile cyber campaign with zero human intervention.

CERT-UA did not specify if LAMEHUG’s execution of the LLM-generated commands was successful, what agencies were targeted, or whether any sensitive data was accessed.

Tags: NCSCUkraineVitaly Simonovich
Previous Post

Deep tech breakthroughs in Ukraine get a boost from Europe

Next Post

Resilience Media Secures Investment, Scales its Editorial Team

Resilience Media

Resilience Media

Start Ups. Security. Defense.

Related News

a view of a city from the top of a building

The UK is setting up meetings between Gulf states and defence tech startups

byIngrid Lunden
March 18, 2026

The last few weeks have seen the UK stepping up its direct military engagement in the Middle East to defend...

Sille Pettai steps down from CEO role at SmartCap

Sille Pettai steps down from CEO role at SmartCap

byFiona Alston
March 17, 2026

Big news in European defence tech investment. Sille Pettai, the CEO of SmartCap -- the Estonian state-owned investment fund --...

100 Startups to Watch in 2026

100 Startups to Watch in 2026

byLeslie Hitchcockand1 others
March 17, 2026

Defence has long been the domain of primes. The war in Ukraine has changed that by introducing the tech sector...

person on top of brown steel frame

How Ukraine is transforming its battlefield data into a world-first AI training hub

byThomas Macauley
March 16, 2026

After four years effectively as an all-in-one laboratory, training ground and live arena for technology to fight its own war,...

US and UK ballistic missile defence capabilities brought into focus as Iran lashes out against region

US and UK ballistic missile defence capabilities brought into focus as Iran lashes out against region

byTom Pashby
March 12, 2026

The ballistic missile defence capabilities of the US, UK and other allies have been put to the test as the...

Scout Ventures raises $125 million to expand investment in defence and dual-use tech

Scout Ventures raises $125 million to expand investment in defence and dual-use tech

byJohn Biggs
March 11, 2026

Scout Ventures has closed its fifth fund with $125 million in commitments, according to an announcement released March 10. The...

The signal is the weapon: How mobile networks became infrastructure for modern war

The signal is the weapon: How mobile networks became infrastructure for modern war

byJohn Biggs
March 11, 2026

Mobile World Congress (MWC) has been around since 1987. The conference, part trade fair, part consumer electronics expo, and part...

Hadean, the AI battle simulation startup, closes bridge round ahead of a Big B

Hadean, the AI battle simulation startup, closes bridge round ahead of a Big B

byIngrid Lunden
March 11, 2026

London-based Hadean began life several years ago as an AI gaming startup working on VR and video simulations, but it...

Load More
Next Post
Welcome to Resilience Media

Resilience Media Secures Investment, Scales its Editorial Team

SEB Expands Defence-Sector Investment Access, Launches Thematic Fund for Europe’s Strategic Resilience

SEB Expands Defence-Sector Investment Access, Launches Thematic Fund for Europe’s Strategic Resilience

Most viewed

InVeris announces fats Drone, an integrated, multi-party drone flight simulator

Uforce raises $50M at a $1B+ valuation to build defence tech for Ukraine

Auterion, the drone software startup, eyes raising $200M at a $1.2B+ valuation

Twentyfour Industries emerges from stealth with $11.8M for mass-produced drones

Senai exits stealth to help governments harness online video intelligence

Palantir and Ukraine’s Brave1 have built a new AI “Dataroom”

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions

© 2026 Resilience Media

No Result
View All Result
  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.