APT28 targets Ukrainian defense sector using AI-powered Lamehug malware
Lamehug is integrated with Qwen 2.5-Coder-32B-Instruct, a powerful LLM accessed via the HuggingFace API.
Lamehug is integrated with Qwen 2.5-Coder-32B-Instruct, a powerful LLM accessed via the HuggingFace API.
The zero-day flaw, tracked as CVE-2025-53770, allows unauthorized attackers to remotely execute code on vulnerable systems.
The group is using stolen credentials and OTP seeds to regain access to devices even after security updates have been applied.
The flaw stems from insufficient validation of untrusted input in ANGLE and GPU.
Authorities identified a 33-year-old French national as the organizer of the illegal operation.
The operation resulted in seven international arrest warrants, including for two alleged ringleaders residing in Russia.
The group may have gained access to sensitive military, law enforcement, and intelligence-sharing data.
Through the initiative, selected researchers will work on identifying flaws in key technologies.
GLOBAL GROUP relies on IABs for network infiltration, with targets including vulnerable edge devices from Fortinet, Palo Alto, and Cisco.
The campaign involves a new Windows backdoor, dubbed ‘HazyBeacon’, that utilizes AWS Lambda URLs for C2 communication.
Showing elements 611 - 620