Armored Likho is changing the front end of its espionage operation, not just sending more phishing mail. The campaign pairs spear-phishing with AI-generated first-stage loaders, so the code defenders see at first contact can vary fast while the rest of the malware stack stays reusable.
Kaspersky says the active campaign targets government and electric power organizations in Russia, Kazakhstan, and Brazil. It also adds BusySnake Stealer, a previously undocumented Python infostealer for Windows, plus a cookie-stealing module, which points to credential theft and follow-on module delivery as part of a modular intrusion chain.
That mix matters because blocking one loader does not break the operation. The actor can swap the first stage and keep using the same downstream stealers and loaders, which makes attachment-based trust and signature-based detection less reliable for this class of campaign.