Opening PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine on Rogue Agent Watch.

Confirmed · Primary sourcing · AI load-bearing · High severity.

In its November 2025 GTIG AI Threat Tracker, Google's Threat Intelligence Group reported that in June 2025 the Russian government-backed actor APT28 (FROZENLAKE) used new malware it tracks as PROMPTSTEAL — reported by CERT-UA as LAMEHUG — against Ukraine. The malware queried a large language model (Qwen2.5-Coder-32B-Instruct via the Hugging Face API) to generate Windows commands at runtime for system reconnaissance and document collection, which were executed and the output exfiltrated. Google describes it as its first observation of malware querying an LLM deployed in live operations.

Data: Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, CC BY-SA 4.0.