Bipko Digital News & Media Platform

collapse
Home / Daily News Analysis / Armored Likho APT Targeting Government, Electric Power Entities

Armored Likho APT Targeting Government, Electric Power Entities

Jul 23, 2026  Twila Rosenbaum  3 views
Armored Likho APT Targeting Government, Electric Power Entities

A newly identified advanced persistent threat (APT) actor, tracked as Armored Likho by Kaspersky researchers, has been conducting targeted attacks against government agencies and electric power organizations in Russia, Brazil, and Kazakhstan. The group's activities encompass both financially motivated attacks on individuals and sophisticated cyber-espionage operations aimed at stealing sensitive information from critical infrastructure sectors.

The Armored Likho threat actor leverages a diverse malware toolkit that includes modular remote access trojans (RATs) and information stealers. Central to its arsenal is the Python-based BusySnake Stealer, a sophisticated piece of malware designed to maintain stealthy control over compromised systems. Additionally, the group uses Go2Tunnel for remote access and network tunneling, enabling persistent connections to victim networks.

Malware Arsenal and Techniques

BusySnake Stealer is a Python-based infostealer that employs multiple evasion techniques to avoid detection. It dynamically decrypts bytecode only when a function is called and immediately re-encrypts it after execution. The malware runs in the background without a console window, making it difficult for users to notice its presence. Its capabilities include clipboard theft, file enumeration, extraction of 64-character hexadecimal keys, document exfiltration, screenshot capture, archiving screenshots, persistence checks, and command execution based on instructions from the command-and-control (C&C) server.

Upon receiving commands, BusySnake can capture screenshots, exfiltrate logged keystrokes, decrypt stored passwords from Chromium-based and Firefox browsers, extract browser cookies, scrape the machine for one-time password (OTP) keys, locate cryptocurrency wallets, harvest Telegram session tokens and credentials, and even restart the legitimate remote desktop tool RustDesk to capture user credentials. This extensive functionality allows attackers to gain comprehensive access to victim systems and sensitive data.

Initial Access and Delivery Mechanism

Armored Likho primarily relies on spear-phishing emails as the initial attack vector. The emails contain archives with executable files or LNK files. When opened, these files display decoy documents to distract the victim while the malware is silently installed in the background. The group has been observed using GitHub repositories to host early development builds and test samples of the malware. The LNK files fetch a Python 3.12 interpreter and an archive from these repositories, which then executes the BusySnake Stealer.

Historically, before adopting BusySnake, Armored Likho used Go2Tunnel to establish reverse SSH tunnels for remote access. However, the group has now integrated this tunneling capability directly into the infostealer, allowing attackers to maintain persistent remote access and interactive control over compromised systems without relying on separate tools.

Overlap with Eagle Werewolf Group

Kaspersky researchers noted significant overlaps between Armored Likho and another APT group known as Eagle Werewolf. Eagle Werewolf was previously associated with the AquilaRAT malware, which shares a similar structure and persistence mechanism with BusySnake Stealer. This suggests that Armored Likho may be an evolution of Eagle Werewolf or that the two groups share common developers or resources. The use of Python-based malware and the preference for targeting government and energy sectors further reinforces the connection.

The emergence of Armored Likho highlights the evolving threat landscape for critical infrastructure. Electric power organizations are particularly attractive targets for nation-state actors seeking to disrupt essential services or gather intelligence. Governments also face constant espionage threats from APT groups that aim to steal classified information or influence policy decisions.

Defense Recommendations

Organizations in the government and energy sectors should implement robust email security measures to detect spear-phishing attempts. Employee training on identifying suspicious emails and attachments is crucial. Additionally, deploying endpoint detection and response (EDR) solutions can help identify malicious activity such as the execution of Python interpreters from unusual sources. Network segmentation and strict access controls can limit the lateral movement of attackers once they gain initial access.

Kaspersky recommends monitoring for unusual outbound connections to GitHub repositories or unknown C&C servers. The use of file integrity monitoring and behavioral analysis tools can also aid in detecting the stealthy techniques employed by BusySnake Stealer. Regular patching of systems and applications further reduces the attack surface.

The Armored Likho APT represents a persistent and evolving threat to government and electric power entities. Its sophisticated malware, combined with effective spear-phishing tactics, makes it a significant concern for cybersecurity teams worldwide. Continued monitoring and intelligence sharing are essential to counter this and similar threats.


Source: SecurityWeek News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy