MYSEC.TV

Home   /   RESOURCES   /   MYSEC.TV   / AI attackers on adoption curve with first report of a novel malware strain

AI attackers on adoption curve with first report of a novel malware strain

Tech & Sec Weekly
SHARE:

IN THIS VIDEO

We speak with Ryan Fetterman of Foundation AI with Splunk in Boston at .conf25. For the past three years, Ryan has been part of the SURGe security research team at Splunk. This team focuses on strategic security research and the modern-day problems of the blue team. Recently, SURGe has joined with intelligence researchers who have also come to Cisco, and now part of a team called Foundation AI, that’s focused on developing security domain focused language models.

Ryan highlights a recent case, initially reported in July 2025 by Ukraine’s CERT-UA which first publicly released a report on a novel malware strain dubbed LameHug, attributing it to APT28 with moderate confidence. The Python-based malware (delivered as .pif, .exe, and .py files compiled via PyInstaller) had no static defaults — instead, it contains base64-encoded prompts that are decoded at runtime and sent to the Qwen 2.5-Coder-32B-Instruct model through the Hugging Face API. The LLM responds with system-appropriate commands (e.g., for reconnaissance or document collection), which the malware immediately executes on the victim host — enabling truly dynamic, on-the-fly adaptation during an active attack.

From the defensive perspective, Ryan confirms there is a lot of opportunity to apply AI in the SOC, because so much of what the SOC does is fundamentally about producing and consuming the logs and CTI and trying to make sense out of that, generate reports and share that information back out. These areas fundamentally align with the core strengths of large language models, which is natural language understanding, natural language generation. But Ryan warns, that attackers are also on an adoption curve. And as much as we’re trying to figure out the natural fit for AI solutions on defense, they’re trying to do the same things on offense.

MySecurity Media attended .conf25 courtesy of Splunk.

#mysecuritytv #splunkconf25 #SplunkSecurity

OTHER VIDEOS IN THIS SERIES

spban
December 10, 2025
We speak with Professor Andrew Dempster, Director of the Australian Centre for Space Engineering Research discussing the PNT 2026 Conference – 4-6 February 2026 at Royal Randwick, Sydney.Watch Now
bann
December 10, 2025
We speak with Deepak Waghmare, CTO for APAC at Dell Technologies at Canalys APAC Forum 2025, held in Da Nang, Vietnam. Deepak, breaks down the rapidly evolving AI landscape, stressing that AI is still in its early stages and must deliver real business outcomes to gain lasting traction.Watch Now
banner-1
December 8, 2025
Luke Taylor, CEO of New Zealand–based managed security provider SSS, joins us on the sidelines of Canalys APAC Forum 2025, held in Da Nang, Vietnam to discuss the company’s sharp focus on identity, access, PKI and privileged access management.Watch Now
techsec-01
November 28, 2025
We cross to Orlando, Florida and speak with Yuriy Tsibere, Product Manager at ThreatLocker. We dive into the ThreatLocker DAC dashboard, built right into the ThreatLocker agent.Watch Now