AI Incident Database - Incident 1220
Source evidence cited by public records. This page shows where the source is used, its trust tier, and when it was last checked in the seed.
Records using this source
- national-security-and-intelligence-stakeholders
entity | 4 June 2026 | 70%
national-security-and-intelligence-stakeholders - organisation named in the AI Incident Database harm index.
- alibaba
entity | 4 Oct 2025 | 70%
alibaba - organisation named in the AI Incident Database harm index.
- apt28
entity | 4 Oct 2025 | 70%
apt28 - organisation named in the AI Incident Database harm index.
- fancy-bear
entity | 4 Oct 2025 | 70%
fancy-bear - organisation named in the AI Incident Database harm index.
- government-of-ukraine
entity | 4 Oct 2025 | 70%
government-of-ukraine - organisation named in the AI Incident Database harm index.
- hugging-face
entity | 4 Oct 2025 | 70%
hugging-face - organisation named in the AI Incident Database harm index.
- national-cybersecurity-infrastructure-of-ukraine
entity | 4 Oct 2025 | 70%
national-cybersecurity-infrastructure-of-ukraine - organisation named in the AI Incident Database harm index.
- public-sector-information-systems
entity | 4 Oct 2025 | 70%
public-sector-information-systems - organisation named in the AI Incident Database harm index.
- state-institutions-targeted-by-espionage-operations
entity | 4 Oct 2025 | 70%
state-institutions-targeted-by-espionage-operations - organisation named in the AI Incident Database harm index.
- ukrainian-government-ministries
entity | 4 Oct 2025 | 70%
ukrainian-government-ministries - organisation named in the AI Incident Database harm index.
- ukrainian-government-officials
entity | 4 Oct 2025 | 70%
ukrainian-government-officials - organisation named in the AI Incident Database harm index.
- LAMEHUG Malware Reportedly Integrates Large Language Model for Real-Time Command Generation in a Purported APT28-Linked Cyberattack
event | 4 Oct 2025 | 82%
Ukraine's CERT-UA and Cato CTRL reported LAMEHUG, the first known malware to integrate a large language model (Qwen2.5-Coder-32B-Instruct via Hugging Face) for real-time command generation. Attributed with moderate confidence to APT28 (Fancy Bear), the malware reportedly targeted Ukrainian officials through phishing emails. The LLM is reported to have dynamically generated reconnaissance and data-exfiltration commands executed on infected systems.