Artificial Intelligence

LameHug: World’s First AI Malware Uses ChatGPT-like Tech to Hack Computers, Exposed by Ukraine Cybersecurity Team

LameHug: The World’s First AI-Based Malware Using ChatGPT-Like Technology

Artificial Intelligence has revolutionized everything from productivity to creativity — but it also comes with serious risks. A dangerous new malware named LameHug has been discovered, and it’s unlike anything we’ve seen before. What makes it unique is that it doesn’t rely on traditional malware tactics. Instead, it uses advanced AI language models like those behind ChatGPT, Gemini, and Claude to carry out cyberattacks.

The malware has been identified by Ukraine’s national cybersecurity team CERT-UA, and initial findings link it to the Russian cyber threat group APT-28, also known as Fancy Bear. Let’s take a deeper look into how LameHug operates and why it may signal a new era of AI-driven cyber threats.

Who is behind LameHug?

According to CERT-UA, the malware attacks originated from APT-28, a state-sponsored Russian hacker group known for launching large-scale cyber-espionage operations globally. In this incident, the hackers targeted Ukrainian government officials by impersonating ministry personnel through phishing emails.

How does LameHug work?

LameHug is written in Python and uses the Hugging Face API along with an open-source language model named Qwen-2.5-Coder-32B-Instruct, developed by Alibaba Cloud. This combination allows the malware to act intelligently — generating shell commands and interacting with the host system without the need for hardcoded logic.

Instead of static instructions, LameHug leverages AI to understand its environment and take dynamic actions, much like how ChatGPT can respond to user queries with tailored outputs.

It steals sensitive data from your computer

Using the same language model principles that allow AI tools to convert text prompts into code, LameHug converts simple prompts into executable system commands. It quietly extracts files from Windows PCs — targeting folders like Documents, Downloads, and Desktop — then transfers them to a remote command-and-control server.

This makes detection extremely difficult since it behaves like a human-in-the-loop system rather than conventional malware.

How was the attack delivered?

Hackers used phishing emails sent to Ukrainian officials, pretending to be from a government ministry. The emails contained a ZIP file disguised as a legitimate tool. Inside were two files: AI_generator_uncensored_Canvas_PRO_0.9.exe and image.py.

Once executed, the malware activated and allowed remote access to system information. It quietly began scanning the infected system for files and uploading the data to a hacker-controlled server.

No more need for writing malware manually

According to cybersecurity platform IBM X-Force Exchange, this is the first documented case of LLMs being used to generate malware commands on-the-fly. This shift means attackers no longer need to develop complex custom malware to infiltrate systems.

This approach also enables them to bypass traditional antivirus programs and forensic tools, since no recognizable malware signatures are involved — only dynamically generated AI instructions.

What does this mean for the future?

The emergence of LameHug signals a new frontier in cybersecurity threats — where AI not only assists defenders but also empowers attackers. This AI-powered malware can operate intelligently, adapt to the system environment, and steal data with minimal human intervention.

Cybersecurity experts believe that this could be the beginning of a wave of AI-driven cyber threats. If left unaddressed, tools like LameHug could be used to orchestrate stealthier, more damaging, and harder-to-trace attacks on organizations worldwide.

Nilesh Khodke

Nilesh Khodke is a technology writer at eTechHunter, where he covers the latest tech news, smartphone launches, gadgets, AI developments, and digital trends. He focuses on delivering accurate, well-researched, and easy-to-understand articles that help readers stay informed in the fast-changing world of technology.

Recent Posts

iQOO Z11x 5G Launched in India With 7200mAh Battery, Dimensity 7400 Turbo Processor: Price, Specification

iQOO Z11x 5G launched in India with a 7,200mAh battery, MediaTek Dimensity 7400 Turbo processor, 120Hz display and 50MP camera.…

March 12, 2026

Vivo Y51 Pro 5G Launched in India With 7,200mAh Battery, 50MP Camera and 120Hz Display

Vivo Y51 Pro 5G launched in India with a 7,200mAh battery, MediaTek Dimensity 7360-Turbo processor, 50MP camera and 120Hz display.…

March 11, 2026

Xiaomi 17 Ultra Launched in India With 200MP Leica Camera, Snapdragon 8 Elite Gen 5: Price, Features

Xiaomi launches the Xiaomi 17 Ultra in India featuring a 200MP Leica telephoto camera with continuous optical zoom, Snapdragon 8…

March 11, 2026

Xiaomi 17 Launched in India With Snapdragon 8 Elite Gen 5, 6,330mAh Battery and Leica Triple 50MP Cameras

Xiaomi launches the Xiaomi 17 in India with Snapdragon 8 Elite Gen 5 chipset, Leica triple 50MP cameras, 120Hz OLED…

March 11, 2026

Realme Note 80 launched with 6.74-inch display and 6300mAh battery

Realme Note 80 launched globally with a 6.74-inch 90Hz display, Unisoc T7250 processor, 6300mAh battery, and Android 15. Check price,…

March 9, 2026

Nothing Phone (4a) Series Launched Globally and in India with Transparent Design, Glyph Lighting and Powerful Hardware

Nothing has officially introduced its latest smartphones, the Nothing Phone (4a) and Nothing Phone (4a) Pro, in global markets as…

March 6, 2026