AI-Generated Malware Powers New Armored Likho APT Campaign
ID: cdb33c7f-abd0-581f-b884-bcfe8a886a7e
STIX ID: report--cdb33c7f-abd0-581f-b884-bcfe8a886a7e
Feed Name: Security Affairs
**Executive summary:** Kaspersky documents an active Armored Likho APT campaign using AI-generated loaders, NSIS and LNK-based droppers (including ZDI-CAN-25373 abuse), and a Python infostealer named BusySnake Stealer to target government and electric power organizations in Russia, Kazakhstan, and Brazil; the toolkit includes obfuscated RATs, Go2Tunnel/embedded reverse SSH tunneling, credential and OTP harvesting, persistence via scheduled tasks/COM, sandbox-evasion techniques, and observable C2 infrastructure (159.198.41.140, 159.198.32.222, grked.online).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
