← All stories
● Covered by 2 sources · 2 reportsMedium impact

Armored Likho Targets Government and Power Sectors with Malware Attacks

🔄 Updated 88d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Armored Likho targets government, power sectors.
  • Operations span Russia, Brazil, Kazakhstan.
  • Employs BusySnake Stealer, Go2Tunnel tools.
  • Focuses on financial and espionage goals.
  • Possible overlap with Eagle Werewolf group.

Overview of Armored Likho Activities

Armored Likho, a newly identified threat actor, is deploying malware campaigns targeting government agencies and the electric power sector. The operations currently span Russia, Brazil, and Kazakhstan, posing significant cybersecurity threats to critical infrastructure.

Kaspersky conducted the technical analysis revealing that Armored Likho engages in both cyber espionage and financially motivated attacks, using sophisticated tooling, including the BusySnake Stealer and Go2Tunnel for remote access.

Tools and Techniques Used

The group's toolkit is diverse, featuring modular RATs and information stealers specifically designed to bypass dynamic analysis. The BusySnake Stealer, a Python-based malware, is a part of this arsenal, enabling the group to exfiltrate credentials and sensitive information stealthily.

Armored Likho uses spear-phishing for initial access, employing archives with executables or LNK files that download malware when opened. This technique helps them maintain prolonged access to compromised networks.

Potential Affiliations and Significance

There are possible overlaps between Armored Likho and the threat cluster known as Eagle Werewolf, active since May 2023, known for attacking government and defense entities involved in UAV development.

Understanding Armored Likho's operations is crucial for enhancing cybersecurity measures in affected regions, particularly in protecting critical infrastructure from similar threat actors.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Kaspersky reveals Armored Likho, an APT targeting government and electric power sectors in multiple countries. The group employs advanced malware, including BusySnake Stealer, to execute financially motivated attacks and cyber-espionage, showcasing significant threats to critical infrastructure.

Armored Likho is attributed to cyber attacks against government agencies and the power sector in Russia, Brazil, and Kazakhstan. The group utilizes advanced malware techniques, including BusySnake Stealer and tools like Go2Tunnel, to maintain persistent access and steal sensitive data.