‘BusySnake’ Infostealer Slithers into Critical Infrastructure Networks

A sophisticated threat group known as “Armored Likho” has infiltrated critical infrastructure networks in Russia, Brazil, and Kazakhstan, leaving a trail of sensitive data theft in its wake. This brazen campaign, which has been ongoing for several months, has caught the attention of cybersecurity researchers at Kaspersky, who have dubbed it one of the most sophisticated malware toolkits they’ve ever seen.

The group’s tactics are nothing short of ingenious. They launch attacks via spear-phishing emails that masquerade as official government communications or social assistance documents. These emails contain malicious archive files disguised as legitimate documents, which in turn launch a matching decoy application or benign-looking document to distract the victim while executing the next stage of the attack.

One particularly insidious variant observed by Kaspersky displayed what appeared to be a legitimate psychological survey, while secretly extracting and executing additional malware in the background. This level of sophistication is made possible by the group’s use of large language models (LLMs) to generate code and comments that blend seamlessly into the malware.

The final stage payload, dubbed “BusySnake Stealer,” is a previously undocumented Python-based infostealer capable of harvesting sensitive information from victim systems, including browser-stored passwords and cookies, clipboard contents, cryptographic keys, and more. BusySnake can also establish reverse SSH tunnels or deploy remote-access software to maintain persistent interactive access.

What sets BusySnake apart from other malware variants is its use of commercial code obfuscation tools like PyArmor Pro to encrypt the Python bytecode, making detection and reverse engineering significantly harder. The malware runs silently without opening a console window and employs an unconventional lock-file mechanism to prevent multiple copies from executing simultaneously.

This campaign highlights several disturbing trends in the world of cybersecurity. Armored Likho’s technical maturity is a testament to the evolving threat landscape, where attackers are increasingly using AI tools to generate complex malware. Furthermore, the group’s use of tool polymorphism and modular architecture makes analysis and detection exponentially more difficult.

The fact that this campaign has targeted critical infrastructure organizations in multiple countries raises serious concerns about the potential for widespread disruption and data compromise. As we move forward in this ever-changing threat landscape, it’s essential to stay vigilant and adapt our security measures to keep pace with the evolving tactics of sophisticated attackers like Armored Likho.

So what can you do to protect yourself? First and foremost, be cautious when receiving unsolicited emails or attachments, especially if they appear to be from official sources. Verify the authenticity of such communications before opening any files or executing software. Furthermore, ensure that your security measures are up-to-date and capable of detecting and responding to advanced threats like BusySnake. Stay informed about emerging trends in cybersecurity, and don’t hesitate to seek expert advice if you’re unsure about how to protect yourself or your organization from these types of attacks.


Source: Dark Reading — 2026-07-06