logo

Angry Likho: Inside a Rapidly Growing Espionage Threat Targeting Eastern Europe

ID: 5fac7920-8769-59cb-a33e-e28ba750b667

STIX ID: report--5fac7920-8769-59cb-a33e-e28ba750b667

Feed Name: Brandefense Blog

Threat Score
82/100

Date Published: 2025-12-17

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

Angry Likho is profiled as a mid-tier APT focused on espionage against government, military, and critical infrastructure targets across Eastern Europe (notably Ukraine, Poland, the Baltic states, and Moldova). The report documents their reliance on realistic phishing lures, minimalistic modular malware (PowerShell/C#, macro loaders, clipboard monitors, credential harvesters), short-lived/cloud-aware C2 infrastructures, persistence via scheduled tasks and registry keys, and evolving OPSEC through 2025 — concluding with defensive recommendations including stronger phishing defenses, MFA, cloud monitoring, and behavioral EDR.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.