Armored Likho Hits Government, Energy Sectors With BusySnake Stealer
ID: 6a5d13e0-59e8-5f71-be12-7d145657a2bc
STIX ID: report--6a5d13e0-59e8-5f71-be12-7d145657a2bc
Feed Name: HackRead
**Executive Summary:** Kaspersky identifies a previously undocumented threat actor dubbed Armored Likho running an active spear-phishing campaign against government and electric power organizations in Russia, Kazakhstan, and Brazil that delivers a Python-based infostealer (BusySnake) via NSIS droppers and malicious LNKs; the malware harvests credentials, session tokens, cookies, screenshots and crypto wallets, implements persistence and reverse SSH, and the operators use AI-generated payloads to hinder attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
