Rogue Agent Watch › Records › promptsteal-apt28-lamehug

PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine

Disclosed · added to the index · last updated

Grades

Verification status
Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
Severity
High — Significant confirmed harm to one or more organizations.

Summary

In its November 2025 GTIG AI Threat Tracker, Google's Threat Intelligence Group reported that in June 2025 the Russian government-backed actor APT28 (FROZENLAKE) used new malware it tracks as PROMPTSTEAL — reported by CERT-UA as LAMEHUG — against Ukraine. The malware queried a large language model (Qwen2.5-Coder-32B-Instruct via the Hugging Face API) to generate Windows commands at runtime for system reconnaissance and document collection, which were executed and the output exfiltrated. Google describes it as its first observation of malware querying an LLM deployed in live operations.

Impact as stated

Live-operations use of an LLM to dynamically generate reconnaissance and document-collection commands on victim systems in Ukraine, with the collected output exfiltrated. Likely relied on stolen API tokens, per Google.

Facts as stated by sources

Actor
APT28 (FROZENLAKE), Russian government-backed (Nation-state)
Category
AI-orchestrated campaign
Models named
Qwen2.5-Coder-32B-Instruct
Model families
Qwen (Alibaba)
Agentic autonomy level
Supervised-autonomous
Guardrail bypass
Open-weight model
Attack lifecycle phases
Reconnaissance, Execution, Exfiltration
Target sectors
not stated
Target countries
UA
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

MITRE ATLAS
AML.T0102, AML.T0016.002

Map points

  • origin: Russia (state sponsor of APT28, per GTIG) (illustrative, country-level centroid; sponsor attribution, per Google Threat Intelligence Group; RU)
  • target: Ukraine (target, per GTIG) (illustrative, country-level centroid; victim location, per Google Threat Intelligence Group; UA)

Related records

Sources (2)

  1. GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools
    Google Threat Intelligence Group · Vendor report · · archived copy
  2. Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly
    The Hacker News · News · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "promptsteal-apt28-lamehug". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/promptsteal-apt28-lamehug.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction