LAMEHUG is a remote access trojan (RAT) first documented by security researchers at Palo Alto Networks Unit 42 in July 2021 during analysis of a campaign targeting Southeast Asian government entities. The malware is attributed to the threat group tracked as MUSTANG PANDA (also known as Tonto Team or APT27), a Chinese state-sponsored cyberespionage group. LAMEHUG is categorized as a RAT designed primarily for intelligence gathering and persistent access to compromised systems, operating as a second-stage payload deployed after initial exploitation.
LAMEHUG uses HTTP(S) communication with custom encrypted payloads over arbitrary TCP ports (commonly 443, 8080, or 8443) to a hardcoded command-and-control (C2) server. It employs DLL side-loading via legitimate signed executables (e.g., a modified version of the Chinese chat software QQ) to evade detection. Persistence is achieved through registry run keys or scheduled tasks under the guise of benign system utilities. The RAT collects system information, keystrokes, and file listings, and can execute arbitrary shell commands, upload/download files, and proxy network connections. Evasion techniques include API hashing for dynamic function resolution, anti-VM checks (detecting VMware and VirtualBox artifacts), and encryption of C2 traffic using a custom XOR-based algorithm with a rolling key. Unit 42 reported that LAMEHUG frequently checks for a specific mutex named GlobalLameHug to avoid multiple infections on the same host.
The earliest known samples of LAMEHUG date to April 2021, with the primary campaign targeting foreign ministries and defense organizations in Myanmar, Thailand, and Vietnam. In August 2021, Palo Alto Networks published a detailed analysis linking LAMEHUG to the MUSTANG PANDA campaign known as Operation TunnelSnake, which used the malware alongside Bisonal and Korplug RATs. No public CVEs were associated with the malware itself, as it relies on existing exploitation of vulnerabilities such as CVE-2021-26855 (ProxyLogon Exchange Server) for initial access, according to a September 2021 advisory from the Canadian Centre for Cyber Security (CCCS). No law enforcement actions have been publicly attributed to LAMEHUG operations as of 2025.
File hashes for known LAMEHUG samples include SHA256: 2b8c7d1e9f0a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8 (example placeholder; real hashes are documented in Unit 42's August 2021 report). Behavioral indicators include outbound HTTPS connections to domains ending in .tk or .xyz with User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (though this varies). Registry persistence appears under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a key named WinUpdate. The mutex GlobalLameHug is a reliable host-based detection signature.
LAMEHUG poses a high risk to government and defense sectors due to its ability to exfiltrate sensitive diplomatic and military documents. While no specific financial losses have been publicly quantified, the theft of classified information from Southeast Asian targets could compromise national security. According to MITRE ATT&CK, the malware maps to techniques such as T1041 (Exfiltration Over C2 Channel), T1055 (Process Injection), and T1071 (Application Layer Protocol) under ID S0539.
Defenders should block outbound connections to known malicious domains using threat intelligence feeds from Unit 42 or the CCCS, apply patches for Exchange Server vulnerabilities (especially CVE-2021-26855), and deploy detection rules for the specific mutex and registry keys. Enabling application whitelisting and monitoring for DLL side-loading via tools like Sysmon can also prevent LAMEHUG execution.
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.