← Back to news

Armored Likho APT Targeting Government, Electric Power Entities

SecurityWeek06/07/2026, 15:10
Read full article →

Summary

AI-Generated

Key Points:

  • Armored Likho, an advanced persistent threat (APT) actor, is targeting government and electric power entities in Russia, Brazil, and Kazakhstan using a combination of cyber-espionage and financially motivated attacks.
  • The impact includes the exfiltration of sensitive information such as credentials and documents, with the potential for persistent remote access to compromised systems via modular malware like BusySnake Stealer.
  • Recommended actions include implementing robust email filtering to block spear-phishing attempts, monitoring for unusual outbound connections, and employing endpoint detection and response (EDR) solutions to identify and mitigate the presence of RATs.

Technical Details: Armored Likho utilizes spear-phishing emails with malicious LNK files that deploy Python-based BusySnake Stealer. This malware employs various evasion techniques, including dynamic bytecode decryption and background execution without a console window.

MITRE ATT&CK Techniques:

  • T1566.001 - Phishing: Spearphishing Attachment (Initial Access)
  • T1059.001 - Command and Scripting Interpreter: Python (Execution)
  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
  • T1041 - Exfiltration Over Command and Control Channel (Exfiltration)

IOCs Mentioned: None mentioned.

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.