Researchers Uncover a Growing Cyber Threat
Armored Likho is a threat group targeting government organizations and the power sector. Researchers observed attacks in several countries, including Russia, Brazil, and Kazakhstan. Moreover, the group combines financial crime with cyber espionage. Therefore, its campaigns create risks for both public institutions and critical infrastructure.
Researchers explained that the attackers use advanced remote access tools and information stealers. However, they also customize malware for different victims. As a result, they can maintain long-term access and steal valuable information. This flexible approach increases the campaign’s effectiveness.
Phishing Starts the Infection
The attack usually begins with a spear-phishing email. For example, the message may appear as an official government notice or public program. However, the attachment contains a malicious archive instead of a legitimate document. Therefore, opening the file starts the infection.
The archive delivers a dropper that downloads additional malware. Moreover, the dropper creates scripts that erase evidence and launch the main payload. It also establishes persistence through scheduled tasks. Consequently, the malware continues running after every system restart.
BusySnake Stealer Collects Sensitive Data
Researchers identified a new information stealer called BusySnake. The malware targets Windows systems and waits for instructions from a remote server. Moreover, it uses several techniques to avoid security detection. Therefore, investigators face greater challenges during analysis.
BusySnake steals clipboard data, documents, browser cookies, and passwords. It also records keystrokes and captures screenshots. Furthermore, it collects cryptocurrency wallet files and messaging application data. As a result, attackers gain access to valuable personal and organizational information.
Attackers Expand Remote Access
The malware supports several remote administration features. For example, it can establish encrypted remote tunnels and execute additional commands. Moreover, it can activate remote desktop software if it already exists on the device. Therefore, attackers can interact with compromised systems more easily.
Researchers also found that the malware can capture login screens. Consequently, attackers may steal user credentials during authentication. This feature increases the chance of account compromise. It also supports broader network intrusion.
Advanced Evasion Makes Detection Harder
BusySnake uses multiple techniques to remain hidden. However, it decrypts its code only when needed and quickly encrypts it again. Therefore, many traditional security tools struggle to inspect its behavior. The malware also runs silently without displaying a visible console window.
Researchers discovered a newer version of the malware as well. Moreover, it manages attack tasks more efficiently through an improved command system. This enhancement allows better communication with attacker-controlled servers. As a result, campaigns become more organized and reliable.
Researchers found similarities between BusySnake and earlier malware families. Therefore, they believe the same threat actor may operate several related campaigns. They also noticed that some malware components appeared to use AI-assisted code generation. However, the attackers continue refining their techniques over time.
The latest campaign integrates more capabilities into a single malware package. Consequently, attackers need fewer external tools during an attack. This change helps reduce detection opportunities. It also increases the overall efficiency of the campaign.
How to Prevent Armored Likho Attacks
Organizations should train employees to recognize spear-phishing emails and suspicious attachments. Moreover, they should apply security updates quickly and monitor scheduled tasks for unusual activity. Continuous security monitoring and managed detection and response services can identify hidden malware before it spreads across the network.
Regular security awareness training also helps users recognize phishing attempts and reduces the risk of credential theft and unauthorized remote access.
Sleep well, we got you covered.

