A newly identified and previously undocumented cyber threat actor, dubbed Armored Likho, has been linked to a series of sophisticated cyberattacks targeting critical infrastructure and governmental entities across Russia, Brazil, and Kazakhstan. This revelation, detailed in a technical analysis by cybersecurity firm Kaspersky, uncovers a group with a dual modus operandi, blending financially motivated campaigns against private individuals with targeted cyber espionage aimed at high-value organizations. The emergence of Armored Likho underscores the evolving landscape of cyber threats, where adversaries deploy increasingly complex toolkits and sophisticated evasion techniques to achieve their objectives.
A Dual Threat: Espionage and Financial Malice
Armored Likho’s operational profile is distinguished by its opportunistic yet highly strategic approach. While engaging in financially motivated campaigns that target private individuals, presumably for monetary gain through data exfiltration or direct theft, the group simultaneously executes targeted cyber espionage missions against governmental bodies and the vital electric power sector. This dual motivation suggests either a versatile, multi-faceted criminal enterprise or a state-sponsored entity leveraging financially lucrative side-operations to fund or mask its primary espionage activities. The choice of targets—critical infrastructure and government agencies—highlights the group’s intent to acquire sensitive information, disrupt essential services, or potentially lay groundwork for future, more impactful attacks. The geographic spread across Russia, Brazil, and Kazakhstan indicates a broad scope of interest, potentially influenced by geopolitical factors or the identification of specific vulnerabilities within these regions.
Kaspersky’s analysis highlights the group’s preference for highly obfuscated and modular Remote Access Trojans (RATs) and information stealers. These tools are meticulously engineered to bypass dynamic analysis, a common technique used by security researchers and automated systems to detect malicious behavior. By integrating such advanced evasion capabilities, Armored Likho significantly prolongs its presence within compromised networks, making detection and eradication challenging for even well-resourced security teams. The use of Go2Tunnel, a specialized tool for remote access and network tunneling, further exemplifies the group’s commitment to maintaining persistent, covert access to compromised hosts. This extensive arsenal enables Armored Likho to exfiltrate credentials and sensitive data, and to dynamically deliver additional malicious modules tailored to the specific characteristics and vulnerabilities of each victim’s profile.
Connecting the Threads: Armored Likho and Eagle Werewolf
Further deepening the mystery surrounding Armored Likho, the Russian cybersecurity vendor Kaspersky has identified potential overlaps with another threat cluster tracked by BI.ZONE under the moniker Eagle Werewolf. This group has been actively operating since at least May 2023, exhibiting a similar pattern of targeting government and defense organizations. Notably, Eagle Werewolf has shown a particular interest in entities involved in Unmanned Aerial Vehicle (UAV) development and manufacturing, a sector of increasing strategic importance globally.
The shared methodologies and tools between Armored Likho and Eagle Werewolf provide critical insights into the potential origins or affiliations of the newly discovered actor. BI.ZONE’s intelligence suggests that Eagle Werewolf also employs a diverse set of tools, including droppers, RATs, and utilities for establishing SSH tunnels – a direct parallel to Armored Likho’s use of Go2Tunnel. This strong resemblance in operational tactics and tool selection implies a possible collaboration, a shared developer base for their malware, or even that Armored Likho could be a rebranding or a subgroup of the broader Eagle Werewolf operation.

A significant event illustrating Eagle Werewolf’s capabilities occurred in February 2026, when the group was observed compromising a drone-focused Telegram channel. This tactic allowed them to distribute AquilaRAT, another sophisticated remote access trojan, via a Rust dropper that deceptively masqueraded as a checklist for Starlink device activation. This method of leveraging legitimate-looking content within a trusted communication channel (Telegram) for malware distribution is a testament to the group’s social engineering prowess and technical sophistication. The use of a Rust dropper further indicates an embrace of modern programming languages to evade traditional security detections, as Rust-compiled binaries can sometimes be less familiar to legacy antivirus engines. The common thread of using Go2Tunnel to establish reverse SSH tunnels to command-and-control (C2) servers using private keys further solidifies the suspected link between Armored Likho and Eagle Werewolf, suggesting a shared infrastructure or a common playbook for maintaining covert communications.
BusySnake Stealer: A Comprehensive Data Extractor
One of the most notable discoveries in Armored Likho’s arsenal is a previously unreported Python-based information stealer named BusySnake Stealer. This malware specifically targets Windows systems and demonstrates a wide array of data exfiltration capabilities. The initial versions of BusySnake were observed to include modules for stealing cookies from web browsers, providing attackers with access to authenticated sessions and potentially sensitive personal data.
The functionalities of BusySnake are extensive and designed for maximum impact:
- C2 Communication: Establishes robust communication with a C2 server, awaiting incoming instructions and dynamically reporting operational statuses (SCHEDULED, IN_PROGRESS, SUCCEEDED, FAILED) for improved task management.
- Screenshots: Capable of taking screenshots at designated intervals, capturing visual information of the victim’s desktop activity.
- Keylogging: Logs keystroke data, allowing the capture of sensitive input like passwords, financial details, and private communications.
- Cryptocurrency Wallet Files: Gathers cryptocurrency wallet files, particularly those with a JSON extension, which are common for various digital currencies.
- Telegram Session and Credential Data: Steals session tokens and credential information from Telegram, granting attackers unauthorized access to messaging accounts.
- Reverse SSH Tunneling: Utilizes Go2Tunnel, now integrated directly into the stealer, to establish reverse SSH tunnels to C2 servers, ensuring covert and persistent access.
- RustDesk Exploitation: Installs or exploits existing RustDesk, an open-source remote desktop software. If RustDesk is already present, the stealer prompts the victim for credentials, captures a screenshot of the input, and exfiltrates it to the C2 server, effectively hijacking remote access capabilities.
- Browser Data Extraction: Extracts cookies and stored passwords from popular web browsers, including Mozilla Firefox and Chromium-based browsers (e.g., Google Chrome, Microsoft Edge).
BusySnake employs multiple advanced evasion techniques to complicate static analysis and circumvent detection by security solutions. A key feature is its dynamic decryption of bytecode, where code is only decrypted at the exact moment a function is called, and then immediately re-encrypted afterward. This makes it incredibly difficult for static analysis tools to fully understand the malware’s functionality without dynamic execution. Furthermore, the malware runs silently in the background without spawning a console window, a characteristic indicated by its PYW file extension, which further aids in its stealth. The sophistication of BusySnake Stealer, especially its comprehensive data exfiltration and evasion capabilities, underscores Armored Likho’s advanced technical acumen.
Deconstructing the Attack Chains
Armored Likho’s initial compromise mechanisms are multi-layered, beginning with highly targeted spear-phishing campaigns. These emails are crafted with compelling lures, often impersonating official government notices or social program announcements, to entice recipients into opening malicious attachments or clicking on deceptive links. This social engineering component is crucial, as it exploits human trust and urgency to bypass initial security perimeters.
One common attack chain involves the distribution of a RAR archive containing malicious executable (EXE) binaries. These EXEs act as droppers, initiating the infection process by retrieving additional payloads from a GitHub repository, including the BusySnake Stealer. Once executed, the dropper malware systematically creates two Visual Basic Script (VBScript) files. One VBScript is typically responsible for erasing forensic traces of the initial execution, hindering incident response efforts. The second VBScript is designed to ensure the stealer’s persistence by launching it via a scheduled task, guaranteeing the malware runs automatically even after system reboots.

An alternate and equally insidious attack chain leverages Windows shortcuts (LNK files) instead of EXE payloads. This method weaponizes a now-patched vulnerability, CVE-2025-9491 (also known as ZDI-CAN-25373), which relates to how Windows handles these shortcut files. Exploiting this flaw results in remote code execution, a critical capability for attackers. The vulnerability was addressed by Microsoft as part of its Patch Tuesday updates in November 2025. This particular vulnerability has a history of widespread exploitation; evidence unearthed by Trend Micro indicated that it had been weaponized by at least a dozen different hacking groups since 2017, highlighting its long-standing utility to malicious actors.
In the LNK-based attack chain documented by Kaspersky, the shortcut vulnerability is abused to trigger the execution of an obfuscated PowerShell command. This command, designed to evade detection, launches a loader responsible for displaying a decoy document—a technique to distract the victim and make the compromise less apparent—while simultaneously preparing the environment for the execution of the Python stealer. Similar to the EXE-based chain, the malware establishes persistence through a combination of a VBScript file and a scheduled task, reinforcing its foothold on the compromised system.
The Shadow of CVE-2025-9491: A Persistent Vulnerability
The exploitation of CVE-2025-9491 by Armored Likho underscores a critical and often overlooked aspect of cybersecurity: the enduring lifespan of certain vulnerabilities. Despite being patched in November 2025, the fact that this LNK shortcut flaw was actively exploited by numerous groups since 2017 speaks volumes about the challenges of universal patch adoption and the ingenuity of threat actors in leveraging known weaknesses. Such vulnerabilities offer a reliable entry point for attackers, allowing them to bypass modern security measures by exploiting fundamental operating system behaviors. The ability of Armored Likho to incorporate such a well-worn but still effective exploit into its repertoire demonstrates a practical, results-oriented approach to compromising targets. The remote code execution capability afforded by CVE-2025-9491 provides attackers with a significant advantage, often allowing them to gain initial access and then escalate privileges or deploy further payloads with relative ease. This incident serves as a stark reminder for organizations to prioritize timely patching and to implement robust vulnerability management programs that account for both new and legacy weaknesses.
The Rise of AI in Cyber Warfare
A particularly intriguing observation from Kaspersky’s analysis is the presence of redundant comments and code blocks within the first-stage payloads, specifically the loaders and stagers. This characteristic strongly suggests that these components were likely generated with the assistance of artificial intelligence (AI) tools. The implications of AI’s role in cyberattacks are profound. For threat actors, AI can significantly lower the barrier to entry, enabling less skilled individuals or groups to generate sophisticated malware components quickly and efficiently. It can also accelerate the development cycle of new tools, allowing attackers to adapt more rapidly to defensive countermeasures.
Furthermore, AI-generated code, especially if it incorporates obfuscation techniques, can make attribution more challenging for cybersecurity researchers. The presence of "redundant comments" might be an artifact of large language models attempting to mimic human coding styles without fully understanding the functional necessity of each line. As AI tools become more advanced and accessible, their integration into cyberattack toolkits is expected to become more widespread, leading to a potential surge in the volume and sophistication of threats. This trend demands a parallel advancement in defensive AI capabilities, creating a new arms race in the digital domain.
Implications for Global Cybersecurity and Critical Infrastructure

The activities of Armored Likho carry significant implications for global cybersecurity, particularly concerning critical infrastructure and governmental stability. Attacks on the electric power sector, as observed in Russia, Brazil, and Kazakhstan, can lead to widespread outages, economic disruption, and even pose risks to public safety. The interconnected nature of modern power grids means that a successful breach in one area could have cascading effects across national or even international boundaries. For governments, successful cyber espionage can result in the theft of state secrets, compromise national security initiatives, and undermine public trust. The collection of sensitive data, including defense-related information (especially concerning UAV development), could have long-term strategic consequences for affected nations.
The dual motivation of Armored Likho—financial gain and espionage—also highlights the blurred lines between cybercrime and state-sponsored activities. This complexity makes attribution difficult and complicates international efforts to combat such threats. The global reach of these attacks, spanning three continents, suggests either a highly capable and well-resourced criminal organization or a state actor with diverse interests and a global operational footprint. Regardless of the exact origin, the discovery of Armored Likho underscores the persistent and evolving threat landscape that critical sectors worldwide must contend with.
Expert Recommendations and Future Outlook
In response to threats like Armored Likho, cybersecurity experts universally emphasize the critical need for proactive and multi-layered defense strategies. Organizations, especially those in government and critical infrastructure, must prioritize robust cybersecurity measures. These include:
- Enhanced Phishing Awareness Training: Regularly educating employees on identifying and reporting spear-phishing attempts is paramount, as this remains a primary initial access vector.
- Timely Patch Management: Implementing stringent patch management protocols to ensure all systems, especially operating systems and critical applications, are updated promptly to mitigate known vulnerabilities like CVE-2025-9491.
- Advanced Threat Detection: Deploying sophisticated Endpoint Detection and Response (EDR) and Security Information and Event Management (SIEM) solutions capable of detecting complex malware behaviors and C2 communications.
- Network Segmentation: Segmenting networks to limit lateral movement of attackers once an initial breach occurs, thereby containing potential damage.
- Multi-Factor Authentication (MFA): Mandating MFA for all accounts, particularly for accessing sensitive systems, to significantly reduce the risk of credential theft.
- Regular Security Audits and Penetration Testing: Continuously assessing security postures to identify weaknesses before attackers can exploit them.
Kaspersky’s findings conclude by highlighting several concurrent trends exemplified by Armored Likho: the group’s growing technical maturity, the increasing prevalence of tool polymorphism (where malware components are constantly modified to evade detection), and a discernible shift toward more complex schemes designed to bypass security solutions. This includes sophisticated Python source code obfuscation and the embedding of network mechanisms, such as Go2Tunnel’s reverse-tunneling functionality, directly into the malware code rather than relying on standalone utilities. This aggressive refinement and modification of their core toolkit indicates a highly adaptable and persistent adversary. The ongoing cat-and-mouse game between threat actors and defenders will only intensify as groups like Armored Likho continue to innovate, demanding constant vigilance and adaptation from cybersecurity professionals globally.
The emergence of Armored Likho serves as a stark reminder that the digital battlefield is constantly evolving. With its blend of financial motivation and cyber espionage, sophisticated toolset, and demonstrated ability to exploit known vulnerabilities and leverage emerging technologies like AI, this threat actor poses a significant challenge. The interconnectedness of global networks and the critical nature of the targeted sectors necessitate a collaborative and proactive approach from governments, cybersecurity firms, and organizations worldwide to defend against such pervasive and adaptable threats.
