Threats · 70 days ago
Armored Likho is changing the front end of its espionage operation, not just sending more phishing mail. The campaign pairs spear-phishing with AI-generated first-stage loaders, so the code defenders see at first contact can vary fast while the rest of the malware stack stays reusable.
Kaspersky says the active campaign targets government and electric power organizations in Russia, Kazakhstan, and Brazil. It also adds BusySnake Stealer, a previously undocumented Python infostealer for Windows, plus a cookie-stealing module, which points to credential theft and follow-on module delivery as part of a modular intrusion chain.
That mix matters because blocking one loader does not break the operation. The actor can swap the first stage and keep using the same downstream stealers and loaders, which makes attachment-based trust and signature-based detection less reliable for this class of campaign.
4 sources covering this story
BusySnake Stealer Slithers Into Critical Infrastructure Networks
A threat group researchers call "Armored Likho" has gained access to government agencies and electrical power entities in Russia, Brazil, and Kazakhstan.
Armored Likho APT Targeting Government, Electric Power Entities
The threat actor uses modular RATs and information stealers in financially motivated and cyber espionage campaigns.
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
Kaspersky says the attacks use phishing, GitHub-hosted payloads, CVE-2025-9491 LNK abuse, and Go2Tunnel-based tunneling.
Armored Likho's new weapon: BusySnake Stealer
An inside look at the active Armored Likho APT campaign.
Part of the PlainSec briefing for 2026-07-07