Also known as: Eagle Werewolf, tracked as, APT29, Cozy Bear, CL-STA-1114, TA488, UNK_PitStop, Void Blizzard, Mirage Kitten, Smoke Sandstorm, Subtle Snail, Africa, South, Earth Preta, HoneyMyte, Twill Typhoon, citing tactical, infrastructure patterns, MuddyRot, MuddyViper, Mango Sandstorm, Static Kitten, TA450, UAC-0063, Parisite, Pioneer Kitten, UNC757, Awaken Likho, PseudoGamaredon, UNC1549, Cav3rn, APT37
Armored Likho has evolved into a hybrid attacker that employs both classic phishing delivery methods and modern code‑generation practices. A recent campaign demonstrated the launch of spear‑phishing emails carrying either executable or LNK attachments to government and electricpower entities; upon execution, the malware—an AI‑generated Python infostealer named BusySnake Stealer—launches a highly obfuscated payload using PyArmor Pro that is difficult to analyze via static methods. Once operative, BusySnake harvests browser credentials from DPAPI and NSS libraries, captures screenshots, logs keystrokes, and collects cryptocurrency wallet files and 2‑factor authentication tokens. The adversary establishes reverse SSH tunnels or utilizes Go2Tunnel for remote persistence and creates scheduled tasks to stay resident on compromised hosts. Communication with command‑and‑control is dynamic so the actors can deploy additional modules at will. Armored Likho also exploits cross‑site scripting (XSS) vulnerabilities in Microsoft Outlook Web Access (OWA) and Zimbra, injecting malicious code that installs backdoors such as NightLedger, BridgeHead, and ArcBridge. The group hosts and distributes components via publicly accessible GitHub repositories by blending legitimate development environments with malicious payloads—a tactic designed to obfuscate malicious activity. The combination of AI‑generated code, modular architecture, virtualization evasion, and use of public code hosting platforms indicates a maturity level aligned with prominent nation‑state groups. Their primary motivation remains long‑term espionage coupled with financial gain through credential theft.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Armored Likho, also known as Eagle Werewolf, is a sophisticated state‑aligned adversary that blends AI‑generated Python malware with traditional spear‑phishing and web exploitation techniques to conduct long‑term espionage and financial theft. The group targets government ministries, electric power utilities, and other critical infrastructure across Russia, Brazil, Kazakhstan, and wider Eurasia, leveraging obfuscated infostealers such as BusySnake Stealer and custom backdoors like OctLurk and SilkLurk for persistence and lateral movement.
Goals & Targeting
Armored Likho’s strategic objectives center on harvesting high‑value credentials from government agencies, utility operators, and other critical infrastructure to support espionage campaigns and potentially monetize obtained data or cryptocurrency assets. The geographic emphasis—Russia, Brazil, Kazakhstan, and additional Eurasian countries—suggests a focus on geopolitical targets with access to sensitive national security or energy sector information. By leveraging both social engineering (phishing) and software vulnerabilities (XSS), the actor tailors its attacks to specific victim profiles, maximizing impact while minimizing detection.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The group conducts coordinated, multi‑phase campaigns that begin with spear‑phishing or web exploitation to gain footholds in critical sectors. Operational tempo is moderate; the actor deploys new modules periodically and updates existing payloads via dynamic C2. Victim selection focuses on government ministries, electricity utilities, telecommunications operators, and other infrastructure providers across Russia, Brazil, Kazakhstan, Iraq, Iran, Turkey, Egypt, Canada, the US, and Australia. Notable past operations include the recent BusySnake infiltration of Russian ministries and Brazilian power firms, as well as prior use of XSS in OWA to deliver NightLedger backdoors to regional targets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the core attributes—identity, modus operandi, and tool usage—is high due to corroborating reports from Kaspersky, SecureList, and CISA. However, gaps remain regarding the precise timelines, full geographic spread, and attribution certainty for all aliases listed (e.g., APT29, Cozy Bear). Additional intelligence on long‑term persistence mechanisms and lateral movement paths would further solidify threat assessment.
No campaigns linked yet.
No observed data linked yet.
3
Techniques
49
Tools
0
Campaigns
35
IOCs
0
Observed Data
1
Tactics