New “LameHug” Malware Deploys AI
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-11182 | Unauthenticated Cross-Site Scripting (XSS) in MDaemon Email Server Webmail MDaemon Email Server versions before 24.5.1c contain a cross-site scripting flaw (CWE-79) in its handling of HTML email: JavaScript embedded in an img tag is not properly sanitized. A remote, unauthenticated attacker can trigger it simply by sending a crafted HTML email that a webmail user then opens, requiring no privileges but relying on user interaction. Successful exploitation loads attacker-supplied JavaScript in the context of the webmail user's browser window, which could enable session or credential theft and further intrusions from that user's session. Any organization running an affected MDaemon version with users of its webmail client is affected; MDaemon is a commercial on-premises Windows mail server used mainly by small and mid-sized organizations. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-19, and public reporting ties MDaemon exploitation to Russia-linked APT28 (Fancy Bear) campaigns that targeted the email of high-level Ukrainians and their military suppliers. Do: Upgrade to MDaemon Email Server 24.5.1c or later, prioritizing installations whose webmail is exposed to the internet, since the flaw is actively exploited and KEV-listed. Review webmail access and message-viewing logs for suspicious activity, especially in organizations that may be targeted by APT28 (Ukrainian government, military, or defense-supply interests). Federal agencies must follow CISA KEV required actions (apply vendor mitigations per instructions and applicable BOD 22-01 guidance, or discontinue use if mitigations are unavailable) by the required due date. | 5.3 | 18% | KEV |
| moderatetens of thousands of on-premises deployments; plausibly on the order of 10,000–100,000 webmail users |
Full article384 words · extracted from infosecurity-magazine.com · click to collapse
A new malware that leverages an AI-powered large language model (LLM) to generate commands for execution on compromised Windows systems has been identified by Ukrainian authorities.
The National Computer Emergency Response Team of Ukraine (CERT-UA) identified the malware, dubbed LameHug, in new cyber-attacks targeting the nation’s security and defense sector.
The attacks have been linked, with moderate confidence, to the ATP28 hacking group which is known to be controlled by Russian special services.
In an update published on July 17, CERT-UA said emails containing an attachment named “Додаток.pdf.zip” (Attachment.pdf.zip) were disseminated among executive bodies, purportedly sent from a representative of a relevant ministry.
This ZIP archive contained a similarly named file with a .pif extension. This file, converted using the Python-based PyInstaller tool, has been classified by CERT-UA as the malicious software LameHug.
LameHug Malware Leverages Open Source LLM
The malware is developed in Python and relies on the Hugging Face API to interact with the open-source Qwen2.5-Coder-32B-Instruct LLM from Alibaba.
An IBM X-Force OSINT advisory noted that the use of LLMs to generate the execution commands is unique.
“This innovative approach allows threat actors to adapt their tactics during a compromise without needing new payloads, potentially making the malware harder to detect by security software or static analysis tools,” said the X-Force OSINT advisory.
CERT-UA specialists said that a compromised email account was used to disseminate emails containing the malicious software.
A Longstanding Cyber-Threat to Ukraine
APT28 is a group linked with the Russian military intelligence agency (GRU) and is also known as Fancy Bear, Sednit, Pawn Storm, Forest Blizzard and Sofacy Group. It has been active since at least 2004.
It has long been targeting Ukraine with cyber-attacks. In 2023, CERT-US said the threat actor group attempted a cyber-attack against a Ukrainian critical power infrastructure facility.
In 2025, research identified that APT28 had successfully leveraged a zero-day vulnerability in MDaemon Email Server (CVE-2024-11182) against Ukrainian companies.
The group has also been known to target organizations supporting Ukraine in its war effort against the Russian Federation.
In May, it was reported that Western logistics and tech firms delivering aid to Ukraine had been targeted by an APT28 cyber-espionage campaign over the past two years.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/new-lamehug-malware-deploys/