Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Armored Likho's new weapon: BusySnake Stealer

894332174f536c2e1efeda05cba79f8b

TLP:CLEAR
Active

MD5 Hash

Description

Kaspersky uncovered a sophisticated phishing campaign by the APT group Armored Likho, deploying a previously undocumented Python-based infostealer dubbed BusySnake Stealer. The campaign targets government agencies and electric power sectors across Russia, Brazil, and Kazakhstan through spear-phishing emails containing malicious EXE or LNK attachments. BusySnake Stealer features advanced obfuscation using PyArmor Pro, extracts credentials from browsers using DPAPI and NSS libraries, captures screenshots, logs keystrokes, scrapes cryptocurrency wallets and 2FA tokens, and establishes reverse SSH tunnels for remote access. The threat actor leverages AI-generated code for first-stage payloads and distributes components via GitHub repositories. The stealer maintains persistence through scheduled tasks and communicates with C2 infrastructure to receive commands dynamically, representing a significant evolution in the group's technical capabilities.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Armored Likho's new weapon: BusySnake Stealer
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:08
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 894332174f536c2e1efeda05cba79f8b

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.