Thursday 14 May, 2026
[email protected]
Resilience Media
  • About
  • News
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • About
  • News
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

Ukraine warns of AI-powered malware targeting the defence sector

CERT-UA says LAMEHUG malware uses an LLM model to craft commands in real-time and evade detection.

Resilience MediabyResilience Media
August 3, 2025
in News
Photo by charlesdeluvio on Unsplash

Photo by charlesdeluvio on Unsplash

Share on Linkedin

Ukraine’s national cyber authority has issued a warning about what it says is the first known use of large language model-powered malware in active attacks targeting the country’s defence and security sector.

You Might Also Like

Expeditions backs frontier defence AI lab Twin Prime in $10m pre-seed raise

Taiwan’s drone industry is booming — thanks to international exports

Noah Labs is bringing air gapped AI to militaries and governments

According to CERT-UA, Ukraine’s Computer Emergency Response Team, the so-called “LAMEHUG” malware was deployed in a recent campaign that it first uncovered on 10 July. The agency says it assesses, with moderate confidence, that the attacks are the work of APT28, a state-sponsored hacking group aligned with Russia’s military intelligence agency, the GRU.

APT28, also known as UAC-0001 and Fancy Bear, has been linked to several high-profile espionage and sabotage operations around the world, including a string of attacks on UK defence organisations involved in delivering foreign assistance to Ukraine.

Earlier this month, the UK’s National Cyber Security Centre also formally linked Fancy Bear to a cyber campaign targeting Western logistics and technology sectors using the ‘Authentic Antics’ malware, and sanctioned 18 Russian individuals connected to the attacks.

In the Russia-backed group’s latest campaign observed by CERT-UA, the LAMEHUG malware is delivered through phishing emails disguised as communications from Ukrainian ministries. Once opened, a malicious .pif file triggers the LAMEHUG loader, which then connects to an open-source LLM hosted on Hugging Face’s cloud platform. Using Qwen 2.5-Coder-32B-Instruct, a powerful AI model capable of generating code and commands, to dynamically generate commands.

Unlike traditional malware that relies on pre-programmed instructions, LAMEHUG uses the LLM to gather detailed information about the victim’s computer, including hardware specifications, running processes, and network configurations. It then scans for sensitive documents, such as PDFs, Word files, and spreadsheets, before exfiltrating data via encrypted channels.

What makes LAMEHUG particularly dangerous is its stealth and flexibility. Because the malware is generating commands via a public API, its traffic can be hard to distinguish from legitimate AI use within an organisation. This means traditional antivirus tools and endpoint detection platforms may miss it entirely.

Vitaly Simonovich, a threat intelligence researcher at Cato Networks, warns that this marks a turning point in the evolution of cyber threats, where attackers use off-the-shelf generative AI tools to automate reconnaissance, tailor commands, and potentially adapt in real time without further human intervention.

“The discovery of LAMEHUG by CERT-UA marks a significant milestone in the threat landscape,” he told Resilience Media. “The campaign highlights state-sponsored investment in emerging AI technologies for cyber activities, with Ukraine serving as the testing ground for these new capabilities. The relatively simple implementation suggests this is APT28’s attempt at learning how to weaponise LLMs, likely opening the door for more sophisticated AI-driven campaigns in the future.”

This incident also highlights growing concerns about how open-source AI models, often released with minimal restrictions, could be weaponised. While the AI community continues to debate safety and governance, LAMEHUG may prove to be the first real-world case of an LLM being actively used in a hostile cyber campaign with zero human intervention.

CERT-UA did not specify if LAMEHUG’s execution of the LLM-generated commands was successful, what agencies were targeted, or whether any sensitive data was accessed.

Tags: NCSCUkraineVitaly Simonovich
Previous Post

Deep tech breakthroughs in Ukraine get a boost from Europe

Next Post

Resilience Media Secures Investment, Scales its Editorial Team

Resilience Media

Resilience Media

Start Ups. Security. Defense.

Related News

Expeditions backs frontier defence AI lab Twin Prime in $10m pre-seed raise

Expeditions backs frontier defence AI lab Twin Prime in $10m pre-seed raise

byCarly Page
May 14, 2026

European defence-focused VC firm Expeditions has led a $10 million pre-seed investment into Twin Prime, a newly launched frontier AI...

Taiwan’s drone industry is booming — thanks to international exports

Taiwan’s drone industry is booming — thanks to international exports

byPaddy Stephens
May 14, 2026

Among the low-rise offices and monochrome factories of Taichung – a sprawling industrial powerhouse in central Taiwan – nestled down...

Noah Labs is bringing air gapped AI to militaries and governments

Noah Labs is bringing air gapped AI to militaries and governments

byJohn Biggs
May 12, 2026

Murat Işık, CEO and co-founder of Noah Labs, believes the next major cyberwar will not be fought with chatbots or...

Munich facility gives Spire a base for sovereign space capabilities

Munich facility gives Spire a base for sovereign space capabilities

byJohn Biggs
May 8, 2026

Spire Global has opened a satellite manufacturing facility in Munich as European governments push to expand sovereign space and intelligence...

Ukrainian Magura sea drone found in Greek cave near Lefkada

Ukrainian Magura sea drone found in Greek cave near Lefkada

byJohn Biggs
May 8, 2026

Greek authorities are investigating the discovery of an unmanned surface vehicle (USV), known as a Magura V5 waterborne drone, off...

‘One alone isn’t a fighter’: Latvia opens up to allies as NATO DIANA supersizes

Two drones entering from Russia and armed with warheads land in Latvia

byJulia Gifford
May 8, 2026

Update: Late Sunday, 10 May, Latvia's Minister for Defence, Andris Sprūds, resigned from his role. Resilience Media reported earlier that...

black and white computer keyboard

Analysis: Europe’s chip ambitions risk going stale

byPaddy Stephens
May 8, 2026

Headlines warn that helium shortages – caused by the ongoing war in Iran and the wider region – are threatening...

ARX expands Ukraine presence as uncrewed ground robot demand surges

ARX expands Ukraine presence as uncrewed ground robot demand surges

byJohn Biggs
May 7, 2026

The robotic ground war is heating up in Ukraine with companies are sending hundreds of uncrewed ground vehicles (UGVs) to...

Load More
Next Post
Welcome to Resilience Media

Resilience Media Secures Investment, Scales its Editorial Team

SEB Expands Defence-Sector Investment Access, Launches Thematic Fund for Europe’s Strategic Resilience

SEB Expands Defence-Sector Investment Access, Launches Thematic Fund for Europe’s Strategic Resilience

Most viewed

InVeris announces fats Drone, an integrated, multi-party drone flight simulator

Uforce raises $50M at a $1B+ valuation to build defence tech for Ukraine

Auterion, the drone software startup, eyes raising $200M at a $1.2B+ valuation

Palantir and Ukraine’s Brave1 have built a new AI “Dataroom”

Senai exits stealth to help governments harness online video intelligence

Twentyfour Industries emerges from stealth with $11.8M for mass-produced drones

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions

© 2026 Resilience Media

No Result
View All Result
  • Home
  • Subscribe
  • About
  • Events
  • Guest Posts
  • Interview
  • News
  • Resilience Conference London 2026
  • Resilience Conference Copenhagen 2026
  • Resilience Conference Warsaw 2026
  • Startups
  • Venture
  • Weekly Digest

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.