Armored Likho APT Targeting Government, Electric Power Entities

Armored Likho APT Targets Government and Electric Power Entities with Sophisticated Malware

A recent investigation has uncovered a highly skilled advanced persistent threat (APT) actor, dubbed Armored Likho, which has been targeting government and electric power organizations in multiple countries. According to Kaspersky, the group’s operations span Russia, Brazil, and Kazakhstan, and its arsenal includes a range of sophisticated malware tools designed for financial gain and cyber-espionage.

Armored Likho’s attack vector relies heavily on spear-phishing emails containing malicious archives that, when opened, display decoys while installing malware in the background. The loader injected via this executable fetches further malware components from GitHub repositories, including a Python-based infostealer known as BusySnake Stealer. This malware packs multiple evasion techniques and dynamically decrypts bytecode to evade detection.

The BusySnake Stealer is a highly versatile tool that can perform a range of tasks, from clipboard theft and file enumeration to screenshot capture and command execution. It also has the ability to establish a reverse SSH tunnel for persistent remote access and interactive control over the victim’s system. Notably, this functionality was previously handled by a separate tool called Go2Tunnel.

Kaspersky notes that Armored Likho’s operations appear to overlap with those of the Eagle Werewolf hacking group, which has been linked to the use of similar malware tools in the past. The investigation highlights the need for organizations to remain vigilant against sophisticated APT attacks and to implement robust security measures to prevent initial access via spear-phishing emails.

The sophistication of Armored Likho’s malware stack is a testament to the evolving threat landscape, where attackers are increasingly using modular and adaptable tools to achieve their goals. As such, it is essential for organizations to stay informed about the latest threats and to prioritize security awareness training for employees to prevent initial access via phishing attacks.

In practical terms, this means that organizations should be on high alert for suspicious emails containing archives or executable files, even if they appear innocuous. It also emphasizes the importance of implementing robust email filtering and anti-virus solutions, as well as regular security updates and patches to protect against known vulnerabilities. By staying informed and proactive, organizations can reduce their risk exposure to sophisticated APT attacks like those carried out by Armored Likho.


Source: SecurityWeek — 2026-07-06