logo

AI-Generated Malware Powers New Armored Likho APT Campaign

ID: cdb33c7f-abd0-581f-b884-bcfe8a886a7e

STIX ID: report--cdb33c7f-abd0-581f-b884-bcfe8a886a7e

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-07-07

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

**Executive summary:** Kaspersky documents an active Armored Likho APT campaign using AI-generated loaders, NSIS and LNK-based droppers (including ZDI-CAN-25373 abuse), and a Python infostealer named BusySnake Stealer to target government and electric power organizations in Russia, Kazakhstan, and Brazil; the toolkit includes obfuscated RATs, Go2Tunnel/embedded reverse SSH tunneling, credential and OTP harvesting, persistence via scheduled tasks/COM, sandbox-evasion techniques, and observable C2 infrastructure (159.198.41.140, 159.198.32.222, grked.online).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.