A previously undocumented threat actor, Armored Likho, has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. Kaspersky published a technical analysis revealing that Armored Likho blends financially motivated campaigns with targeted cyber espionage, using obfuscated, modular RATs and infostealers designed to bypass dynamic analysis.
The group employs tools like Go2Tunnel for remote access and network tunneling, maintaining persistent access to compromised hosts, stealing credentials and sensitive data, and dynamically delivering modules tailored to the victim’s profile. Kaspersky notes possible overlaps with a threat cluster tracked by BI.ZONE as Eagle Werewolf, active since May 2023, which targets government and defense organizations, including those involved in UAV development, using droppers, RATs, and SSH tunneling utilities.
The attack chain begins with spear-phishing emails using lures related to official government notices or social programs, distributing RAR archives containing EXE binaries that serve as droppers for additional payloads retrieved from a GitHub repository. The dropper creates VBScript files for erasing traces and launching the stealer via scheduled tasks. Alternate chains exploit CVE-2025-9491, a Windows shortcut vulnerability patched in November 2025, to execute obfuscated PowerShell commands that load a decoy document and prepare for the Python-based BusySnake Stealer.
BusySnake Stealer implements multiple evasion techniques, including dynamic bytecode decryption and running without a console window. Its capabilities include stealing clipboard data, enumerating files, uploading documents, capturing screenshots, logging keystrokes, gathering cryptocurrency wallet files, collecting Telegram session data, establishing reverse SSH tunnels via Go2Tunnel, installing RustDesk, and extracting cookies and passwords from browsers. A newer version includes a task-management framework for improved C2 communication. Kaspersky also found signs that first-stage payloads were likely generated with AI assistance.
CVEs: CVE-2025-9491, CVE-2026-55200, CVE-2026-46817
Attack groups: Armored Likho, Eagle Werewolf
Malware: BusySnake Stealer, Go2Tunnel, AquilaRAT, RustDesk
Companies: Kaspersky, BI.ZONE, Trend Micro, Microsoft
Original source: thehackernews.com