Rogue Agent Watch › Records › promptsteal-apt28-lamehug
PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
In its November 2025 GTIG AI Threat Tracker, Google's Threat Intelligence Group reported that in June 2025 the Russian government-backed actor APT28 (FROZENLAKE) used new malware it tracks as PROMPTSTEAL — reported by CERT-UA as LAMEHUG — against Ukraine. The malware queried a large language model (Qwen2.5-Coder-32B-Instruct via the Hugging Face API) to generate Windows commands at runtime for system reconnaissance and document collection, which were executed and the output exfiltrated. Google describes it as its first observation of malware querying an LLM deployed in live operations.
Impact as stated
Live-operations use of an LLM to dynamically generate reconnaissance and document-collection commands on victim systems in Ukraine, with the collected output exfiltrated. Likely relied on stolen API tokens, per Google.
Facts as stated by sources
- Actor
- APT28 (FROZENLAKE), Russian government-backed (Nation-state)
- Category
- AI-orchestrated campaign
- Models named
- Qwen2.5-Coder-32B-Instruct
- Model families
- Qwen (Alibaba)
- Agentic autonomy level
- Supervised-autonomous
- Guardrail bypass
- Open-weight model
- Attack lifecycle phases
- Reconnaissance, Execution, Exfiltration
- Target sectors
- not stated
- Target countries
- UA
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
- MITRE ATLAS
- AML.T0102, AML.T0016.002
Map points
- origin: Russia (state sponsor of APT28, per GTIG) (illustrative, country-level centroid; sponsor attribution, per Google Threat Intelligence Group; RU)
- target: Ukraine (target, per GTIG) (illustrative, country-level centroid; victim location, per Google Threat Intelligence Group; UA)
Related records
Sources (2)
- GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools
Google Threat Intelligence Group · Vendor report · · archived copy - Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly
The Hacker News · News · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "promptsteal-apt28-lamehug". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/promptsteal-apt28-lamehug.json — CC BY-SA 4.0.