LAMEHUG is a malware family referenced in recent threat intelligence coverage.
Overview
LAMEHUG is a malware family referenced in recent threat intelligence coverage. The articles frame it within the expanding ransomware ecosystem and the increasing use of AI-assisted tooling by threat actors, indicating its relevance in modern cybercrime campaigns. Specific technical details (IOCs, TTPs) are not listed in the cited sources.
Related Threat Clusters
-
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that…
6 articles · Updated May 22, 2026 -
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
73 articles · Updated July 24, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Google GTIG Reports Shift in AI Misuse by Cyber Adversaries
The Google Threat Intelligence Group (GTIG) has identified a new operational phase of AI abuse, where adversaries are deploying AI-enabled malware in live operations. This shift indicates that threat actors are moving…
3 articles · Updated November 5, 2025 -
PromptSpy: First Android Malware Utilizing Generative AI Discovered
ESET researchers have identified PromptSpy, the first Android malware to incorporate generative AI, specifically Google’s Gemini, in its execution flow. This malware utilizes AI to manipulate the user interface and…
39 articles · Updated February 19, 2026 -
Rapid7 Q3 2025 Report Details Rise in Ransomware Groups and AI Weaponization
Rapid7's Q3 2025 Threat Landscape Report, released on November 12, 2025, reveals an increase in active ransomware groups from 65 to 88. The report highlights the growing use of generative AI by attackers and a 21%…
2 articles · Updated November 12, 2025 -
Rapid7 Q3 2025 Report Highlights Ransomware Growth and AI Weaponization
Rapid7's Q3 2025 Threat Landscape Report, released on November 12, 2025, reveals a significant increase in active ransomware groups, rising from 65 to 88. The report notes that attackers are increasingly exploiting…
3 articles · Updated November 13, 2025
Recent Intelligence Reports
- FrostArmada — www.lumen.com · August 3, 2026
- 001 — attack.mitre.org · July 23, 2026
- PromptSpy Android malware may exploit Gemini AI — Computerweekly · February 19, 2026
- Rapid7 Q3 Report: 88 Ransomware Groups, New Alliances — Stocktitan · November 12, 2025
- GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools — Mandiant · November 5, 2025