Skip to content
Armored Likho APT Targets Power Grids with BusySnake Stealer Malware

Armored Likho APT Targets Power Grids with BusySnake Stealer Malware

First seen 4 Jul 2026, 15:24 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 5, 2026 at 14:18 UTC

A newly identified APT group, Armored Likho, is conducting a phishing campaign targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. The group employs a sophisticated infostealer known as BusySnake Stealer, which is difficult to detect and recover from. Attack vectors include spear-phishing emails with malicious attachments disguised as legitimate documents. The campaign exploits CVE-2025-9491, urging immediate patching and auditing of scheduled tasks. Armored Likho operates dual tracks of cyber-espionage and financially motivated credential theft, affecting both critical infrastructure and private individuals. The group has been linked to previous activities under the alias Eagle Werewolf, with notable advancements in their malware toolkit. The campaign remains active and poses a significant threat to the targeted sectors.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 92d ago How this analysis works

Timeline

2025-08-26
CVE-2025-9491 published
A critical vulnerability affecting systems used by government and utility sectors was disclosed.
Securelist
2026-07-03
Armored Likho campaign uncovered
Kaspersky revealed the ongoing phishing campaign by Armored Likho targeting critical infrastructure.
Securelist
2026-07-04
Kaspersky publicly names Armored Likho
Kaspersky confirmed the attribution of the cyber-espionage campaign to Armored Likho, detailing their tactics and tools.
Techtimes

More articles in this cluster (7)

Following this threat?

Track Armored Likho, BusySnake Stealer and CVE-2025-9491 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed