Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign
The Securelist report details a new cyber espionage campaign conducted by the Armored Likho (Eagle Werewolf) APT group, targeting government agencies and the electric power sector globally. The group utilizes a sophisticated toolkit including the BusySnake Stealer infostealer, leveraging AI-generated payloads and techniques like Python source code obfuscation to evade detection. The campaign relies heavily on spear-phishing emails containing malicious archive files, and employs a diverse malware stack including RATs, Go2Tunnel, and cookie stealing modules to maintain persistent access and exfiltrate sensitive data.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
