Sunday 3 May, 2026
[email protected]
Resilience Media
  • About
  • News
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • About
  • News
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

Ukraine warns of AI-powered malware targeting the defence sector

CERT-UA says LAMEHUG malware uses an LLM model to craft commands in real-time and evade detection.

Resilience MediabyResilience Media
August 3, 2025
in News
Photo by charlesdeluvio on Unsplash

Photo by charlesdeluvio on Unsplash

Share on Linkedin

Ukraine’s national cyber authority has issued a warning about what it says is the first known use of large language model-powered malware in active attacks targeting the country’s defence and security sector.

You Might Also Like

Spiral Hydrogen raises €2.7M to pilot its new hydrogen tech at the Port of Rotterdam

Report maps Russia’s hybrid war on Poland

Report: Europe’s reliance on imported energy and technology presents both risk and opportunity

According to CERT-UA, Ukraine’s Computer Emergency Response Team, the so-called “LAMEHUG” malware was deployed in a recent campaign that it first uncovered on 10 July. The agency says it assesses, with moderate confidence, that the attacks are the work of APT28, a state-sponsored hacking group aligned with Russia’s military intelligence agency, the GRU.

APT28, also known as UAC-0001 and Fancy Bear, has been linked to several high-profile espionage and sabotage operations around the world, including a string of attacks on UK defence organisations involved in delivering foreign assistance to Ukraine.

Earlier this month, the UK’s National Cyber Security Centre also formally linked Fancy Bear to a cyber campaign targeting Western logistics and technology sectors using the ‘Authentic Antics’ malware, and sanctioned 18 Russian individuals connected to the attacks.

In the Russia-backed group’s latest campaign observed by CERT-UA, the LAMEHUG malware is delivered through phishing emails disguised as communications from Ukrainian ministries. Once opened, a malicious .pif file triggers the LAMEHUG loader, which then connects to an open-source LLM hosted on Hugging Face’s cloud platform. Using Qwen 2.5-Coder-32B-Instruct, a powerful AI model capable of generating code and commands, to dynamically generate commands.

Unlike traditional malware that relies on pre-programmed instructions, LAMEHUG uses the LLM to gather detailed information about the victim’s computer, including hardware specifications, running processes, and network configurations. It then scans for sensitive documents, such as PDFs, Word files, and spreadsheets, before exfiltrating data via encrypted channels.

What makes LAMEHUG particularly dangerous is its stealth and flexibility. Because the malware is generating commands via a public API, its traffic can be hard to distinguish from legitimate AI use within an organisation. This means traditional antivirus tools and endpoint detection platforms may miss it entirely.

Vitaly Simonovich, a threat intelligence researcher at Cato Networks, warns that this marks a turning point in the evolution of cyber threats, where attackers use off-the-shelf generative AI tools to automate reconnaissance, tailor commands, and potentially adapt in real time without further human intervention.

“The discovery of LAMEHUG by CERT-UA marks a significant milestone in the threat landscape,” he told Resilience Media. “The campaign highlights state-sponsored investment in emerging AI technologies for cyber activities, with Ukraine serving as the testing ground for these new capabilities. The relatively simple implementation suggests this is APT28’s attempt at learning how to weaponise LLMs, likely opening the door for more sophisticated AI-driven campaigns in the future.”

This incident also highlights growing concerns about how open-source AI models, often released with minimal restrictions, could be weaponised. While the AI community continues to debate safety and governance, LAMEHUG may prove to be the first real-world case of an LLM being actively used in a hostile cyber campaign with zero human intervention.

CERT-UA did not specify if LAMEHUG’s execution of the LLM-generated commands was successful, what agencies were targeted, or whether any sensitive data was accessed.

Tags: NCSCUkraineVitaly Simonovich
Previous Post

Deep tech breakthroughs in Ukraine get a boost from Europe

Next Post

Resilience Media Secures Investment, Scales its Editorial Team

Resilience Media

Resilience Media

Start Ups. Security. Defense.

Related News

Spiral Hydrogen raises €2.7M to pilot its new hydrogen tech at the Port of Rotterdam

Spiral Hydrogen raises €2.7M to pilot its new hydrogen tech at the Port of Rotterdam

byFiona Alston
April 30, 2026

Estonian-Dutch dual-use startup Spiral Hydrogen will be taking its centrifugal bubble-free electrolysis technology from the lab to the Port of...

Report maps Russia’s hybrid war on Poland

Report maps Russia’s hybrid war on Poland

byJohn Biggs
April 30, 2026

A new report from Defence24 has outlined the role of Russia in a number of cyberattacks and acts of sabotage....

Line illustration showing trucks, cars and a cyclist, alongside a wind turbine, solar panel, power lines, buildings and a data centre, depicting energy infrastructure

Report: Europe’s reliance on imported energy and technology presents both risk and opportunity

byPaul Sawers
April 29, 2026

Europe’s reliance on external technology and infrastructure faces growing scrutiny, as policymakers and industry leaders confront the risks of depending...

Weekly Digest: The mystery of the British unicorn – the story of our dealings with Roark Aerospace

Inside the case of Roark Aerospace: The British defence unicorn no one can verify

byIngrid Lunden
April 28, 2026

On Boxing Day 2025, we received a press release from Roark Aerospace. The UK startup, which makes anti-drone systems, reported...

German military uniform (Touko Aikioniemi from Unsplash)

Europe’s armed forces are too reliant on US cloud providers, report finds

byPaul Sawers
April 28, 2026

Europe’s defence systems depend heavily on US cloud infrastructure, leaving key military functions exposed to potential service disruptions during geopolitical...

UNIVITY raises €27 million to build a 5G satellite constellation that can expand European communication networks

UNIVITY raises €27 million to build a 5G satellite constellation that can expand European communication networks

byJohn Biggs
April 24, 2026

UNIVITY has raised €27 million to transition its space-based telecom infrastructure from a demonstration phase to an early industrial stage....

Jacek Siewiera: a future NATO conflict will be fought against civilian targets

Jacek Siewiera: a future NATO conflict will be fought against civilian targets

byResilience Media
April 24, 2026

The wars in Iran and Ukraine have underscored how civilian infrastructure will become a feature of future conflicts. And Poland’s...

Sten Tamkivi: Poland’s defence start-ups should be seen as future GDP drivers

Sten Tamkivi: Poland’s defence start-ups should be seen as future GDP drivers

byResilience Media
April 24, 2026

Sten Tamkivi, a partner at Plural and an early Skype executive, joined Resilience Media publisher Leslie Hitchcock on stage during...

Load More
Next Post
Welcome to Resilience Media

Resilience Media Secures Investment, Scales its Editorial Team

SEB Expands Defence-Sector Investment Access, Launches Thematic Fund for Europe’s Strategic Resilience

SEB Expands Defence-Sector Investment Access, Launches Thematic Fund for Europe’s Strategic Resilience

Most viewed

InVeris announces fats Drone, an integrated, multi-party drone flight simulator

Uforce raises $50M at a $1B+ valuation to build defence tech for Ukraine

Auterion, the drone software startup, eyes raising $200M at a $1.2B+ valuation

Palantir and Ukraine’s Brave1 have built a new AI “Dataroom”

Senai exits stealth to help governments harness online video intelligence

Twentyfour Industries emerges from stealth with $11.8M for mass-produced drones

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions

© 2026 Resilience Media

No Result
View All Result
  • Home
  • Subscribe
  • About
  • Events
  • Guest Posts
  • Interview
  • News
  • Resilience Conference London 2026
  • Resilience Conference Copenhagen 2026
  • Resilience Conference Warsaw 2026
  • Startups
  • Venture
  • Weekly Digest

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.