HomeSecurityBusySnake Stealer: The Russian-speaking APT that hits energy and government

BusySnake Stealer: The Russian-Speaking APT That Hits Energy and Government

Kaspersky against individuals and cyber espionage against state and energy organizations. The actor, codenamed Armored Likho, has been recorded attacking government agencies and electricity companies in Russia, Brazil, and Kazakhstan, using modular RATs, sophisticated infostealers, and network penetration tools.

The most interesting aspect of the research is not only the geographical spread of the campaign, but the technical maturity of the new tool that accompanies it: a Python-based information thief known as BusySnake Stealer, which combines reverse SSH tunneling via Go2Tunnel and shows architectural similarities to the pre-existing AquilaRAT. As Kaspersky notes, “this diverse arsenal allows the threat actor to maintain covert control over compromised computers, leak credentials and sensitive information, and dynamically deploy downloadable modules tailored to the victim’s profile and needs.”

This publication comes at a time of increased Russian-speaking cyber activity against European state targets, most notably the recent hybrid deepfake attack against the office of the Greek Prime Minister. The two incidents are not technically connected, but their temporal proximity is noteworthy, as explained below.

What is Armored Likho and who is it targeting?

Armored Likho is a previously undisclosed APT group that Kaspersky identified after monitoring phishing campaigns. It is distinguished by its dual nature: on the one hand, it carries out financially motivated attacks against individuals, targeting bank accounts and cryptocurrency wallets, and on the other, it undertakes targeted cyberespionage against state organizations and energy entities.

The confirmed victims are located in three countries: Russia, Brazil , and Kazakhstan. Targets include government agencies, power utilities, and individual users, indicating that the group is tailoring its targeting to the opportunity. The simultaneous targeting of energy infrastructure and government agencies is concerning, as such access could be leveraged not only for data theft but also for a long-term presence in anticipation of future disruption.

Armored Likho APT targets government organizations and energy infrastructure

The attack chain: from spear-phishing to BusySnake Stealer

The entry point is almost always spear-phishing. Attackers send targeted emails with compressed file attachments containing either executables (EXE) or Windows shortcuts (LNK). When the victim opens the attachment, a harmless decoy document appears, while the malware installation process begins silently in the background.

In the LNK files, a fake document is displayed while a Python 3.12 interpreter is downloaded along with a compressed archive containing the rest of the infection. An in-memory loader retrieves additional files from repositories on GitHub , which, according to Kaspersky, contain early development versions and test samples — an indication that the team's toolkit is still actively being developed. The system ends up infected with BusySnake Stealer , along with tools such as Go2Tunnel and, in earlier campaigns, AquilaRAT .

What does BusySnake Stealer do (technical analysis)

BusySnake Stealer is written in Python and stands out for its diligence in avoiding detection, with the most characteristic technique being dynamic bytecode decryption: each piece of code is decrypted only when a function is called and encrypted again immediately afterwards, so that there is never any fully decrypted code available for analysis. It runs entirely in the background, without a console window.

Its functionality is based on separate handlers: stealing data from the clipboard, enumerating files, extracting 64-character hexadecimal keys, leaking documents to the C2, taking screenshots, performing persistence checks, and executing commands. Through the C2, attackers capture screenshots, intercept keystrokes, decrypt passwords from Chromium and Firefox browsers, extract cookies, search for OTPs and cryptocurrency wallets, and harvest sessions and credentials from Telegram. It can also set up a reverse SSH tunnel — a feature now built directly into the tool, rather than provided by the standalone Go2Tunnel— and restart RustDesk to snag victim credentials.

BusySnake Stealer technical analysis and connection with Eagle Werewolf

The Greek dimension: increased Russian-speaking mobility

Kaspersky’s report on Armored Likho does not mention Greek victims and does not in any way link the group to other incidents in Greece. Confirmed victims remain exclusively in Russia, Brazil and Kazakhstan. However, the publication of this research, on July 6, 2026, coincides with a period of intense discussion in Greece about Russian hybrid operations, following the revelation that the Prime Minister’s National Security Advisor, Thanos Dokos, was tricked by Russian pranksters using real-time AI deepfake technologyinto believing he was speaking to his Ukrainian counterpart.

It is important to emphasize that these are two completely different operations, with different techniques, different perpetrators —as far as is known so far— and without any documented connection between them. There is no indication that Armored Likho is involved in the Doku incident, nor that the two cases share infrastructure or tools. What is observed is simply a timing of increased Russian mobility: Russian-speaking threat actors —state-linked or independent, technically advanced like Armored Likho or based on social engineering as in the Doku case— appear to have been escalating their operations against state targets across Europe in parallel in recent months. The conclusion for the Greek cybersecurity community is not that the country is in the crosshairs of this particular campaign, but that the broader threat landscape from Russian-speaking perpetrators requires heightened vigilance.

Associations with Eagle Werewolf and the recommendations

The research finds significant overlaps between Armored Likho and the activity tracked as Eagle Werewolf, reinforced by the similarity between BusySnake Stealer and AquilaRAT — a tool previously used by the same group. The two malware programs share a similar code structure and persistence mechanism, suggesting either a common origin or close collaboration.

For government agencies and energy companies, the core recommendations remain critical: training staff to recognize spear-phishing, strictly checking compressed file and LNK attachments at the email gateway, monitoring unusual traffic to GitHub, and checking for unauthorized use of tools like RustDesk. Given BusySnake’s ability to target credentials from browsers and Telegram, enabling MFA is recommended wherever possible.

See also: ToddyCat: New Umbrij malware targets corporate Gmail accounts

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: PamStealer: New Mac malware confirms passwords

See also: United Kingdom: Cyberattacks from Russia, Iran and China

See also: Dokos and Deepfake: How the attack on Maximou took place and what are the countermeasures

The Armored Likho case confirms a trend that is increasingly being observed: groups that do not clearly fit into either organized crime or state-sponsored espionage, but operate hybridly, leveraging the same technical arsenal for both quick financial gain and long-term access to critical infrastructure (SecurityWeek).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS