Armored Likho, a newly identified threat actor, is deploying malware campaigns targeting government agencies and the electric power sector. The operations currently span Russia, Brazil, and Kazakhstan, posing significant cybersecurity threats to critical infrastructure.
Kaspersky conducted the technical analysis revealing that Armored Likho engages in both cyber espionage and financially motivated attacks, using sophisticated tooling, including the BusySnake Stealer and Go2Tunnel for remote access.
The group's toolkit is diverse, featuring modular RATs and information stealers specifically designed to bypass dynamic analysis. The BusySnake Stealer, a Python-based malware, is a part of this arsenal, enabling the group to exfiltrate credentials and sensitive information stealthily.
Armored Likho uses spear-phishing for initial access, employing archives with executables or LNK files that download malware when opened. This technique helps them maintain prolonged access to compromised networks.
There are possible overlaps between Armored Likho and the threat cluster known as Eagle Werewolf, active since May 2023, known for attacking government and defense entities involved in UAV development.
Understanding Armored Likho's operations is crucial for enhancing cybersecurity measures in affected regions, particularly in protecting critical infrastructure from similar threat actors.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Kaspersky reveals Armored Likho, an APT targeting government and electric power sectors in multiple countries. The group employs advanced malware, including BusySnake Stealer, to execute financially motivated attacks and cyber-espionage, showcasing significant threats to critical infrastructure.
Armored Likho is attributed to cyber attacks against government agencies and the power sector in Russia, Brazil, and Kazakhstan. The group utilizes advanced malware techniques, including BusySnake Stealer and tools like Go2Tunnel, to maintain persistent access and steal sensitive data.