news.mlab.sh
Back to the feed
threat-intel

Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign

High
Image: Securelist
Summary

The Securelist report details a new cyber espionage campaign conducted by the Armored Likho (Eagle Werewolf) APT group, targeting government agencies and the electric power sector globally. The group utilizes a sophisticated toolkit including the BusySnake Stealer infostealer, leveraging AI-generated payloads and techniques like Python source code obfuscation to evade detection. The campaign relies heavily on spear-phishing emails containing malicious archive files, and employs a diverse malware stack including RATs, Go2Tunnel, and cookie stealing modules to maintain persistent access and exfiltrate sensitive data.

Read the full article at Securelist

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.