Thursday 16 April, 2026
[email protected]
Resilience Media
  • About
  • News
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • About
  • News
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

Ukraine warns of AI-powered malware targeting the defence sector

CERT-UA says LAMEHUG malware uses an LLM model to craft commands in real-time and evade detection.

Resilience MediabyResilience Media
August 3, 2025
in News
Photo by charlesdeluvio on Unsplash

Photo by charlesdeluvio on Unsplash

Share on Linkedin

Ukraine’s national cyber authority has issued a warning about what it says is the first known use of large language model-powered malware in active attacks targeting the country’s defence and security sector.

You Might Also Like

ETSI pushes back on EU plan to freeze out ‘high-risk’ players from standards work

Klaus Hommels of Lakestar talks about defence consolidation and the future of procurement

To infinity and back: the opportunity for reusable hardware in space

According to CERT-UA, Ukraine’s Computer Emergency Response Team, the so-called “LAMEHUG” malware was deployed in a recent campaign that it first uncovered on 10 July. The agency says it assesses, with moderate confidence, that the attacks are the work of APT28, a state-sponsored hacking group aligned with Russia’s military intelligence agency, the GRU.

APT28, also known as UAC-0001 and Fancy Bear, has been linked to several high-profile espionage and sabotage operations around the world, including a string of attacks on UK defence organisations involved in delivering foreign assistance to Ukraine.

Earlier this month, the UK’s National Cyber Security Centre also formally linked Fancy Bear to a cyber campaign targeting Western logistics and technology sectors using the ‘Authentic Antics’ malware, and sanctioned 18 Russian individuals connected to the attacks.

In the Russia-backed group’s latest campaign observed by CERT-UA, the LAMEHUG malware is delivered through phishing emails disguised as communications from Ukrainian ministries. Once opened, a malicious .pif file triggers the LAMEHUG loader, which then connects to an open-source LLM hosted on Hugging Face’s cloud platform. Using Qwen 2.5-Coder-32B-Instruct, a powerful AI model capable of generating code and commands, to dynamically generate commands.

Unlike traditional malware that relies on pre-programmed instructions, LAMEHUG uses the LLM to gather detailed information about the victim’s computer, including hardware specifications, running processes, and network configurations. It then scans for sensitive documents, such as PDFs, Word files, and spreadsheets, before exfiltrating data via encrypted channels.

What makes LAMEHUG particularly dangerous is its stealth and flexibility. Because the malware is generating commands via a public API, its traffic can be hard to distinguish from legitimate AI use within an organisation. This means traditional antivirus tools and endpoint detection platforms may miss it entirely.

Vitaly Simonovich, a threat intelligence researcher at Cato Networks, warns that this marks a turning point in the evolution of cyber threats, where attackers use off-the-shelf generative AI tools to automate reconnaissance, tailor commands, and potentially adapt in real time without further human intervention.

“The discovery of LAMEHUG by CERT-UA marks a significant milestone in the threat landscape,” he told Resilience Media. “The campaign highlights state-sponsored investment in emerging AI technologies for cyber activities, with Ukraine serving as the testing ground for these new capabilities. The relatively simple implementation suggests this is APT28’s attempt at learning how to weaponise LLMs, likely opening the door for more sophisticated AI-driven campaigns in the future.”

This incident also highlights growing concerns about how open-source AI models, often released with minimal restrictions, could be weaponised. While the AI community continues to debate safety and governance, LAMEHUG may prove to be the first real-world case of an LLM being actively used in a hostile cyber campaign with zero human intervention.

CERT-UA did not specify if LAMEHUG’s execution of the LLM-generated commands was successful, what agencies were targeted, or whether any sensitive data was accessed.

Tags: NCSCUkraineVitaly Simonovich
Previous Post

Deep tech breakthroughs in Ukraine get a boost from Europe

Next Post

Resilience Media Secures Investment, Scales its Editorial Team

Resilience Media

Resilience Media

Start Ups. Security. Defense.

Related News

waving flag

ETSI pushes back on EU plan to freeze out ‘high-risk’ players from standards work

byCarly Page
April 16, 2026

Europe's telecoms standards body has fired an early warning shot at Brussels’ next cybersecurity overhaul, arguing that plans to shut...

Klaus Hommels of Lakestar talks about defence consolidation and the future of procurement

Klaus Hommels of Lakestar talks about defence consolidation and the future of procurement

byJohn Biggs
April 15, 2026

Investor and entrepreneur Klaus Hommels, founder of Lakestar, sees a new era of European defence spending and investment. His comment?...

To infinity and back: the opportunity for reusable hardware in space

To infinity and back: the opportunity for reusable hardware in space

byResilience Media
April 15, 2026

Germany's Atmos Space Cargo is opening an office in Poland focused on defence capabilities, announced CEO Sebastian Klaus during a...

Danish startup Sapient Perception raises €2M to widen UAV vision for real-time battlefield decisions

Danish startup Sapient Perception raises €2M to widen UAV vision for real-time battlefield decisions

byCarly Page
April 15, 2026

A Danish startup promising to give drones a much wider field of view without sacrificing detail has raised €2 million...

Daimler Truck and ARX Robotics Team Up to Bring AI and Autonomy to Military Vehicles

ARX Robotics secures British Army contract

byLuke Smithand1 others
April 15, 2026

ARX Robotics has secured its first British Army contract, delivering UK-manufactured Gereon uncrewed ground vehicles for Recce-Strike experimentation through Task...

Airship startup Kelluu raises €15M from NATO, its first investment in Finland

Airship startup Kelluu raises €15M from NATO, its first investment in Finland

byIngrid Lunden
April 14, 2026

Defence is a multi-modal concept, and today a startup focused on building a stronger pipeline of intelligence data from a...

Rheinmetall and Destinus to ‘bridge the gap’ with new joint venture

Rheinmetall and Destinus to ‘bridge the gap’ with new joint venture

byFiona Alston
April 13, 2026

The CEO of German defence prime Rheinmetall may have stepped out into the spotlight as an outspoken critic of Ukraine's...

Refute report finds coordinated election interference targeting European voters and diaspora

Refute report finds coordinated election interference targeting European voters and diaspora

byJohn Biggs
April 10, 2026

UK-based Refute has published a new report examining foreign interference in recent European elections, drawing on data from Romania, Moldova,...

Load More
Next Post
Welcome to Resilience Media

Resilience Media Secures Investment, Scales its Editorial Team

SEB Expands Defence-Sector Investment Access, Launches Thematic Fund for Europe’s Strategic Resilience

SEB Expands Defence-Sector Investment Access, Launches Thematic Fund for Europe’s Strategic Resilience

Most viewed

InVeris announces fats Drone, an integrated, multi-party drone flight simulator

Uforce raises $50M at a $1B+ valuation to build defence tech for Ukraine

Auterion, the drone software startup, eyes raising $200M at a $1.2B+ valuation

Senai exits stealth to help governments harness online video intelligence

Palantir and Ukraine’s Brave1 have built a new AI “Dataroom”

Twentyfour Industries emerges from stealth with $11.8M for mass-produced drones

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions

© 2026 Resilience Media

No Result
View All Result
  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.