logo

Armored Likho Hits Government, Energy Sectors With BusySnake Stealer

ID: 6a5d13e0-59e8-5f71-be12-7d145657a2bc

STIX ID: report--6a5d13e0-59e8-5f71-be12-7d145657a2bc

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-07-08

Date Updated: 2026-07-17

Author: Waqas

...
...

**Executive Summary:** Kaspersky identifies a previously undocumented threat actor dubbed Armored Likho running an active spear-phishing campaign against government and electric power organizations in Russia, Kazakhstan, and Brazil that delivers a Python-based infostealer (BusySnake) via NSIS droppers and malicious LNKs; the malware harvests credentials, session tokens, cookies, screenshots and crypto wallets, implements persistence and reverse SSH, and the operators use AI-generated payloads to hinder attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.