A previously undisclosed threat actor, known as Armored Likho, has been attributed to cyberattacks targeting government agencies and the electricity sector in Russia, Brazil, and Kazakhstan.
See also: Awaken Likho group targets Russian government agencies

“ Armored Likho combines financially motivated campaigns targeting individuals with targeted cyberespionage targeting organizations ,” Kaspersky said in a technical analysis published today. “ Their toolkit features obfuscated, modular RATs and infostealers specifically designed to bypass dynamic analysis. ”
The attacks are characterized by the use of tools such as Go2Tunnel for remote access and network tunneling. The wide variety of tools in its arsenal allows the threat actor to maintain persistent access to compromised computers, steal credentials and sensitive data, and dynamically deliver modules tailored to the victim's profile.
The Russian cybersecurity vendor noted that Armored Likho shares potential overlaps with a threat group tracked by BI.ZONE under the alias Eagle Werewolf, which has been active since May 2023. This hacker group has a history of targeting government and defense organizations, especially those involved in the development and construction of UAVs, using droppers, remote access Trojans (RATs), and tools for establishing SSH tunnels.
“Threat actors may use compromised Telegram channels to distribute malware,” BI.ZONE notes in its threat actor description. “While the group’s primary motivation is cyberespionage, campaigns aimed at stealing money from victims have also been documented.”
In February 2026, Eagle Werewolf was observed to have compromised a drone-focused Telegram channel to distribute the AquilaRAT via a Rust dropper pretending to be a checklist for activating Starlink devices. Go2Tunnel was also used to establish a reverse SSH tunnel to a command and control (C2) server using a private key.
See also: Armored Core 6 update adds new locations, new maps

The latest findings indicate that the threat actor has used a previously undisclosed Python-based information stealer called BusySnake Stealer, targeting Windows systems, one version of which includes a module to steal cookies from web browsers. The exact origins of Armored Likho remain unknown.
The starting point of the attack chain is a spear-phishing email that uses baits related to official government notifications or social programs to distribute a RAR archive containing executable EXE files that act as droppers for additional payloads retrieved from a GitHub repository, including the thief's payload.
The dropper malware creates two Visual Basic Script (VBScript) responsible for eliminating traces of the initial execution and launching the thief via a scheduled task.
Alternative chains use Windows shortcuts (LNK) instead of EXE executable payloads that exploit a now-patched vulnerability in how Windows handles such files, resulting in remote code execution. The vulnerability, tracked as CVE-2025-9491 (also known as ZDI-CAN-25373), was patched by Microsoft as part of the November 2025 Patch Tuesday updates. The data revealed that the vulnerability had been exploited by a dozen hacking groups since 2017.
In the attack chain documented by Kaspersky, the shortcut vulnerability is abused to trigger the execution of a malicious PowerShell command that launches a loader responsible for displaying a deceptive document while preparing the environment for the execution of the Python thief. The malware then installs persistence through a combination of a VBScript file and a scheduled task.
See also: Armored Core VI Fires of Rubicon releases update 1.02

The stealer, named BusySnake, employs multiple evasion techniques to make static analysis difficult and to evade detection. Its main goal is to establish communication with a C2 server and then wait for incoming instructions. It also supports functionality to steal data from the system clipboard, enumerate files throughout the system, and record their metadata in a local database.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
