Armored Likho APT Targeting Government, Electric Power Entities

A Sophisticated Threat Actor Targets Government and Electric Power Organizations Worldwide

A highly skilled threat actor, dubbed Armored Likho, has been identified as targeting government and electric power organizations in multiple countries. According to Kaspersky, this advanced persistent threat (APT) group engages in financially motivated attacks against individuals and cyber-espionage operations against organizations in Russia, Brazil, and Kazakhstan.

The threat actor’s arsenal includes a range of sophisticated malware tools, including modular remote access trojans (RATs) and information stealers. Notably, Armored Likho employs the BusySnake Stealer, a Python-based infostealer that allows attackers to exfiltrate sensitive information from compromised hosts. This stealer is equipped with multiple evasion techniques and can dynamically decrypt bytecode when a function is called.

The malware’s command-and-control (C&C) server enables the attackers to remotely access and control victim systems. The BusySnake Stealer can capture screenshots, exfiltrate logged keystroke data, and even restart RustDesk to capture users’ credentials. This level of persistence and interaction raises serious concerns for organizations in the affected countries.

Armored Likho’s tactics, techniques, and procedures (TTPs) have been observed to overlap with those of Eagle Werewolf activity. The threat actor relies on spear-phishing for initial access, using archives attached to emails that contain executables or LNK files. These files display decoys while malware is being installed in the background, making it difficult for victims to detect the infection.

The use of modular malware and dynamic deployment of downloadable modules tailored to the victim’s profile and tasks at hand makes Armored Likho a highly adaptable threat actor. This level of sophistication requires organizations to be vigilant and proactive in their security measures.

In light of this discovery, it is essential for government and electric power organizations to reassess their cybersecurity posture. Implementing robust email filtering, endpoint detection and response (EDR) solutions, and conducting regular vulnerability assessments can help mitigate the risks associated with Armored Likho’s attacks. Moreover, employees should be educated on the dangers of spear-phishing and the importance of reporting suspicious emails.

Ultimately, this incident highlights the need for organizations to invest in robust cybersecurity measures and stay informed about emerging threats. By staying one step ahead of sophisticated threat actors like Armored Likho, organizations can better protect themselves against these complex attacks.


Source: SecurityWeek — 2026-07-06