Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors armored likho

Also known as: Eagle Werewolf, tracked as, APT29, Cozy Bear, CL-STA-1114, TA488, UNK_PitStop, Void Blizzard, Mirage Kitten, Smoke Sandstorm, Subtle Snail, Africa, South, Earth Preta, HoneyMyte, Twill Typhoon, citing tactical, infrastructure patterns, MuddyRot, MuddyViper, Mango Sandstorm, Static Kitten, TA450, UAC-0063, Parisite, Pioneer Kitten, UNC757, Awaken Likho, PseudoGamaredon, UNC1549, Cav3rn, APT37

Description

Armored Likho has evolved into a hybrid attacker that employs both classic phishing delivery methods and modern code‑generation practices. A recent campaign demonstrated the launch of spear‑phishing emails carrying either executable or LNK attachments to government and electricpower entities; upon execution, the malware—an AI‑generated Python infostealer named BusySnake Stealer—launches a highly obfuscated payload using PyArmor Pro that is difficult to analyze via static methods. Once operative, BusySnake harvests browser credentials from DPAPI and NSS libraries, captures screenshots, logs keystrokes, and collects cryptocurrency wallet files and 2‑factor authentication tokens. The adversary establishes reverse SSH tunnels or utilizes Go2Tunnel for remote persistence and creates scheduled tasks to stay resident on compromised hosts. Communication with command‑and‑control is dynamic so the actors can deploy additional modules at will. Armored Likho also exploits cross‑site scripting (XSS) vulnerabilities in Microsoft Outlook Web Access (OWA) and Zimbra, injecting malicious code that installs backdoors such as NightLedger, BridgeHead, and ArcBridge. The group hosts and distributes components via publicly accessible GitHub repositories by blending legitimate development environments with malicious payloads—a tactic designed to obfuscate malicious activity. The combination of AI‑generated code, modular architecture, virtualization evasion, and use of public code hosting platforms indicates a maturity level aligned with prominent nation‑state groups. Their primary motivation remains long‑term espionage coupled with financial gain through credential theft.

Goals & Targeting

Targeted Sectors

Government
Energy
Financial services
Defense
Telecommunications
Critical infrastructure
Aerospace
Non profit
Education
Hospitality
Healthcare
Aviation
Maritime
Oil gas

Targeted Countries / Regions

Brazil
Kazakhstan
Russian Federation
RU
UA
BR
KZ
CN
IN
IR
PK
TW
EG
BY
CA
US
AU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Armored Likho, also known as Eagle Werewolf, is a sophisticated state‑aligned adversary that blends AI‑generated Python malware with traditional spear‑phishing and web exploitation techniques to conduct long‑term espionage and financial theft. The group targets government ministries, electric power utilities, and other critical infrastructure across Russia, Brazil, Kazakhstan, and wider Eurasia, leveraging obfuscated infostealers such as BusySnake Stealer and custom backdoors like OctLurk and SilkLurk for persistence and lateral movement.

Goals & Targeting

Armored Likho’s strategic objectives center on harvesting high‑value credentials from government agencies, utility operators, and other critical infrastructure to support espionage campaigns and potentially monetize obtained data or cryptocurrency assets. The geographic emphasis—Russia, Brazil, Kazakhstan, and additional Eurasian countries—suggests a focus on geopolitical targets with access to sensitive national security or energy sector information. By leveraging both social engineering (phishing) and software vulnerabilities (XSS), the actor tailors its attacks to specific victim profiles, maximizing impact while minimizing detection.

Enhanced Description

Key Capabilities

  • Virtual machine / sandbox evasion detection
  • Adaptive malware behavior based on environment checks
  • AI‑generated malware component creation
  • Custom backdoor families (BusySnake Stealer, OctLurk, SilkLurk)
  • XSS exploitation in Outlook Web Access and Zimbra
  • Use of backdoors and WebSocket tunnelers (NightLedger, BridgeHead, ArcBridge) for covert long‑term access
  • Obfuscated modular RATs and infostealers evading dynamic analysis
  • Network tunneling via Go2Tunnel / SSH tunnels for persistence/lateral movement
  • Credential theft, keystroke logging, screenshots capture
  • Harvest cryptocurrency wallets & 2FA tokens
  • Dynamic C2 allowing module updates
  • Public GitHub usage for component hosting/distribution
  • Scheduled tasks for persistence
  • Spear‑phishing attachment delivery targeting government ministries and utilities

MITRE ATT&CK Tactics

Defense Evasion
Initial Access
Persistence
Credential Access
Command and Control
Exfiltration

ATT&CK Techniques

T1497
T1497.001
T1497.003

Software / Tooling

BusySnake Stealer
OctLurk
SilkLurk
Go2Tunnel
NightLedger
BridgeHead
ArcBridge

Campaigns & Victims

The group conducts coordinated, multi‑phase campaigns that begin with spear‑phishing or web exploitation to gain footholds in critical sectors. Operational tempo is moderate; the actor deploys new modules periodically and updates existing payloads via dynamic C2. Victim selection focuses on government ministries, electricity utilities, telecommunications operators, and other infrastructure providers across Russia, Brazil, Kazakhstan, Iraq, Iran, Turkey, Egypt, Canada, the US, and Australia. Notable past operations include the recent BusySnake infiltration of Russian ministries and Brazilian power firms, as well as prior use of XSS in OWA to deliver NightLedger backdoors to regional targets.

IOC Patterns

  • Virtualization/Sandbox detection checks
  • XSS exploitation in web applications (OWA, Zimbra)
  • Network tunneling via WebSocket/custom tunnelers
  • Obfuscated RAT binaries evading dynamic analysis scanners

Recommended Actions

  • Patch Microsoft Outlook Web Access and Zimbra promptly to close CVE-2026-42897 and CVE-2025-66376
  • Deploy granular web application firewalls that detect and block XSS payloads
  • Implement network monitoring for abnormal WebSocket traffic and tunnel usage
  • Enforce least‑privilege endpoint policies and monitor for RAT signatures
  • Enable security information and event management (SIEM) to correlate credential theft events

Suggested Tags

government-targeting
electric-power-sector
AI-generated-malware
BusySnake
OctLurk
SilkLurk
Eagle Werewolf
APT29
APT
State-sponsored
Russian threat actor
Iranian threat actor
OWA exploitation
Zimbra exploitation
XSS vulnerability
Network tunneling
Remote Access Tool
Cyber‑espionage
Spear‑phishing

Confidence Assessment

The confidence in the core attributes—identity, modus operandi, and tool usage—is high due to corroborating reports from Kaspersky, SecureList, and CISA. However, gaps remain regarding the precise timelines, full geographic spread, and attribution certainty for all aliases listed (e.g., APT29, Cozy Bear). Additional intelligence on long‑term persistence mechanisms and lateral movement paths would further solidify threat assessment.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 6 Filename 5 IPv4 Address 3 MD5 Hash 5 Email Address 1

References

  1. thehackernews.com — Cited by web research for: APT29
  2. thehackernews.com — Cited by web research for: Earth Preta
  3. threats.kaspersky.com — Cited by web research for: T1497.001
  4. securelist.com — Cited by web research for: Dark
  5. https://niccs.cisa.gov/news-events/news — Cited by AI analysis.

Intel Summary

3

Techniques

49

Tools

0

Campaigns

35

IOCs

0

Observed Data

1

Tactics

Tags

APT
Financial Targeting
Phishing
Backdoor / C2
Government Targeting
government-targeting
electric-power-sector
AI-generated-malware
BusySnake
OctLurk
SilkLurk
Eagle Werewolf
APT29
State-sponsored
Russian threat actor
Iranian threat actor
OWA exploitation
Zimbra exploitation
XSS vulnerability
Network tunneling
Remote Access Tool
Cyber‑espionage
Spear‑phishing

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.