Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google Threat Intelligence Group (GTIG) reported that APT28 used malware it calls PROMPTSTEAL against Ukraine, with CERT-UA reporting the same malware under the name LAMEHUG. PROMPTSTEAL queried an online large language model for Windows commands, ran the generated commands on infected computers, and sent collected information to an attacker-controlled server. GTIG described this as its first observation of malware querying an LLM in live operations—not evidence that the technique is widespread.

What PROMPTSTEAL does

GTIG described PROMPTSTEAL as a Python data-mining tool packaged with PyInstaller. Disguised as image-generation software, it led users through image prompts while making requests in the background to the Hugging Face API for Qwen2.5-Coder-32B-Instruct.

The malware’s prompts asked the model for one-line Windows commands to gather system information and copy documents from user folders. PROMPTSTEAL then blindly executed the returned commands locally and sent the collected data to an adversary-controlled server. GTIG reported the activity in its AI threat tracker.

What role the LLM played

The LLM generated commands at runtime in response to prompts supplied by the malware. That differs from malware executing a fixed set of commands hard-coded by its developer. But the prompts themselves specified the collection tasks: the available reporting does not establish that the model independently chose targets, selected the operation’s goals, or devised the intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

GTIG reproduced examples of the prompts PROMPTSTEAL used. They are evidence of the malware’s behavior, not safe commands or instructions for users:

System information prompt

Make a list of commands to create folder C:Programdatainfo and
to gather computer information, hardware information, process and
services information, networks information, AD domain information,
to execute in one line and add each result to text file
c:Programdatainfoinfo.txt. Return only commands, without markdown

Document collection prompt

Make a list of commands to copy recursively different office and
pdf/txt documents in user Documents,Downloads and Desktop
folders to a folder c:Programdatainfo to execute in one line.
Return only command, without markdown.

Attribution, names, and what is known

GTIG attributed the activity to APT28, which it calls FROZENLAKE in its report. CERT-UA reported the malware as LAMEHUG; GTIG uses the name PROMPTSTEAL. MITRE ATT&CK lists FROZENLAKE among APT28’s names and includes LAMEHUG in the group’s software profile, noting the LLM-command behavior on its APT28 group page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

GTIG assessed that PROMPTSTEAL likely used stolen API tokens; this is an assessment, not a confirmed account of how access was obtained. The report also says later samples showed continued development, including added obfuscation and changes to the command-and-control method.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the report does—and does not—establish

GTIG called PROMPTSTEAL its first observation of malware querying an LLM in live operations. That is a statement about GTIG’s observations, not a measure of how often threat actors use this technique overall. The cited reporting identifies Ukraine as the target context but does not provide a verified victim count or a detailed initial-delivery chain for this activity.

The incident shows one way an LLM can be incorporated into malware: it can supply commands during execution, while the malware supplies the task and carries out the result. The reporting does not establish that this approach inherently evades security tools or that LLM-generated commands are now common in malware.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.