Armored Likho is a previously undocumented threat actor assessed with medium confidence to overlap with Eagle Werewolf. The group has conducted spear-phishing campaigns targeting government agencies and organizations in the electric power sector, with confirmed victimology in Russia, Kazakhstan, and Brazil. Its activity appears to combine financially motivated operations against individuals with cyber-espionage against organizations, making it unusual among clusters focused on either theft or intelligence collection alone. Armored Likho relies primarily on socially engineered email lures themed as official notices, social programs, humanitarian assistance, debt-related documents, and similar pretexts. Observed delivery chains use malicious archives containing executable droppers or Windows shortcut files, often paired with decoy content to reduce suspicion while malware is installed in the background. The actor has also been linked to abuse of a Windows shortcut handling issue tracked as ZDI-CAN-25373 and CVE-2025-9491 to conceal malicious command execution. The group’s malware arsenal includes BusySnake Stealer, a Python-based and heavily obfuscated infostealer used as a central payload, as well as tooling associated with reverse SSH tunneling and earlier malware overlaps with AquilaRAT. BusySnake supports credential theft from Chromium-based browsers and Firefox, cookie theft, clipboard monitoring, screenshot capture, file inventorying, document exfiltration, theft of Telegram session data, collection of one-time-password secrets, and searches for cryptocurrency-related material. It also supports persistent remote access through reverse SSH tunneling and remote-control functionality, enabling long-term surveillance and interactive post-compromise operations. BusySnake uses layered evasion and persistence mechanisms, including staged loaders, PowerShell-based execution, on-demand decryption of protected code, background execution without a visible console, and scheduled-task persistence. Newer variants show increased maturity through stealthier task creation methods, delayed execution for anti-analysis, task-state tracking, and in-memory execution of arbitrary Python scripts. Reporting has also noted signs that some first-stage loaders may have been generated with large language models, likely to accelerate variation in delivery tooling and complicate attribution. Attribution to Armored Likho is based on circumstantial but notable overlaps in tooling, architecture, persistence patterns, and tunneling functionality with activity associated with Eagle Werewolf and malware such as AquilaRAT and Go2Tunnel. No specific nation-state attribution is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
53 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a phishing campaign using AI-generated loaders to deploy the BusySnake Stealer against government agencies and electrical power organizations, enabling credential theft, surveillance, data exfiltration, and persistent access.
Conducting an active spear-phishing-led espionage and information-stealing campaign using BusySnake Stealer against government agencies and the electric energy sector.
Conducting espionage and financially motivated intrusions against government agencies, electric power organizations, and private individuals using spear-phishing, AI-generated malware, BusySnake Stealer, RATs, and tunneling tools.
Conducting an ongoing spear-phishing campaign using BusySnake and previously linked AquilaRAT to steal credentials, sensitive documents, session tokens, 2FA secrets, and other high-value data, while maintaining long-term access to government and critical infrastructure environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.