threat-intel
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
High
Summary
Armored Likho, a previously undocumented threat actor, has been actively targeting government agencies and the power sector in Russia, Brazil, and Kazakhstan with a sophisticated campaign utilizing tools like BusySnake Stealer and Go2Tunnel. The group employs obfuscated RATs, spear-phishing emails, and exploits vulnerabilities to gain persistent access, steal data, and conduct cyber espionage, with potential overlaps observed with the Eagle Werewolf threat actor. The attacks leverage techniques like cookie theft and screenshot capture to maximize data exfiltration.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
