BusySnake Stealer is a Python-based Windows infostealer associated with campaigns attributed with medium confidence to the Armored Likho threat actor, also linked by some reporting to Eagle Werewolf. It has been used primarily against government agencies and electric power organizations in Russia, Kazakhstan, and Brazil, while the broader actor activity also includes financially motivated targeting of individuals. The malware is heavily obfuscated with PyArmor and runs silently as a background Python process without a visible console window. Observed delivery chains use spearphishing emails carrying archive files that contain either NSIS-based droppers or malicious Windows shortcut files, with both paths ultimately staging a Python runtime and deploying BusySnake as the final payload.
BusySnake focuses on theft of sensitive user and system data. Confirmed capabilities include extraction of stored passwords from Chromium-based browsers and Firefox, theft of browser cookies, harvesting of Telegram session data, collection of clipboard contents, screenshot capture, file-system inventorying, and exfiltration of selected user documents. It also searches for one-time-password provisioning data, cryptocurrency wallet-related files, and hexadecimal key material. Some reporting further indicates collection of RustDesk-related credentials and other authentication or API-secret material. The malware maintains local state, filters files during collection, and uses a lock mechanism to avoid multiple concurrent instances.
For persistence, BusySnake creates scheduled tasks, with newer variants using the Windows Task Scheduler COM interface instead of simpler command-line task creation. Later versions also introduce delayed execution to hinder dynamic analysis, a task-status framework for command handling, and the ability to fetch and execute arbitrary Python scripts directly in memory, extending the malware beyond pure theft into a broader post-compromise platform.
BusySnake also incorporates remote-access-enabling functionality. It can establish reverse SSH tunnels using parameters supplied by command and control, and it can deploy or restart RustDesk to facilitate operator access. Architectural and functional overlaps have been reported between BusySnake and other tools used by Armored Likho, including Go2Tunnel and AquilaRAT, supporting the assessment that BusySnake is part of a modular and evolving intrusion toolkit used for credential theft, data exfiltration, and sustained access in sensitive Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Un fichier LNK exploitant la vulnérabilité ZDI-CAN-25373 pour masquer des paramètres de ligne de commande via des espaces ou sauts de ligne | BusySnake Stealer — Fonctionnalités principales # L’infostealer est écrit en Python , obfusqué et chiffré via PyArmor Pro 9.2.0 , et s’exécute sans fenêtre console (extension .pyw ).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BusySnake Stealer — Fonctionnalités principales # L’infostealer est écrit en Python , obfusqué et chiffré via PyArmor Pro 9.2.0 , et s’exécute sans fenêtre console (extension .pyw ).
BusySnake Stealer — Fonctionnalités principales # L’infostealer est écrit en Python , obfusqué et chiffré via PyArmor Pro 9.2.0 , et s’exécute sans fenêtre console (extension .pyw ).
33 distinct techniques documented for this family, organized by ATT&CK tactic.
It runs without opening a visible console window and uses scheduled tasks to remain active. In newer samples, the malware creates scheduled tasks through Windows component interfaces instead of directly calling standard task commands, a change intended to reduce detection.
The shortcut launches an obfuscated command and PowerShell process to download a loader, Python components, and the BusySnake payload.
A second path uses a malicious LNK shortcut that hides its command-line activity through spaces and line breaks. The shortcut launches an obfuscated command and PowerShell process
Il est persisté via une tâche planifiée (toutes les 5 minutes) créée par un script VBScript ( run.vbs ).
It runs without opening a visible console window and uses scheduled tasks to remain active. In newer samples, the malware creates scheduled tasks through Windows component interfaces instead of directly calling standard task commands, a change intended to reduce detection.
T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
It runs without opening a visible console window and uses scheduled tasks to remain active. In newer samples, the malware creates scheduled tasks through Windows component interfaces instead of directly calling standard task commands, a change intended to reduce detection.
The executable launches a fake survey, then injects malicious code into another process and retrieves additional payloads from online repositories.
T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
BusySnake is protected with code obfuscation and encryption that only decrypts functions when needed.
The executable launches a fake survey, then injects malicious code into another process and retrieves additional payloads from online repositories.
The stealer can also decrypt saved passwords from Chromium-based browsers and Firefox profiles, extract browser cookies
Recherche de secrets 2FA (pattern otpauth:// ) ... Recherche de wallets crypto (fichiers JSON)
After execution, BusySnake inventories files, watches the clipboard, searches for long hexadecimal keys, and collects documents from Desktop, Documents, and Downloads folders.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Its remote-control features include reverse SSH tunneling, which can give operators a route back into a compromised system even after the initial theft activity.
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Python-based infostealer used in an active campaign attributed with medium confidence to Armored Likho. It steals browser passwords and cookies, logs clipboard activity, inventories files, exfiltrates documents, captures screenshots, steals Telegram data, searches for 2FA secrets and crypto wallets, and can deploy RustDesk for remote control. It also supports reverse SSH tunneling and newer variants can execute arbitrary Python scripts in memory.
A Python-based stealer used to exfiltrate credentials, cryptocurrency keys, API secrets, sensitive documents, Telegram session data, and RustDesk credentials; it also establishes reverse SSH tunnels for operator access.
Python-based infostealer used by Armored Likho that employs evasion techniques, dynamically decrypts bytecode at function call time, steals clipboard data, enumerates files, extracts keys, exfiltrates documents, captures screenshots and keystrokes, decrypts stored browser passwords, extracts cookies, scrapes OTP keys, finds cryptocurrency wallets, harvests Telegram sessions and credentials, and can establish a reverse SSH tunnel for persistent remote access and interactive control.
A previously undocumented Python-based infostealer used as the final-stage payload in Armored Likho campaigns. It harvests browser-stored passwords and cookies, clipboard contents, cryptographic keys, messaging and authentication data, and Telegram session information. It can also establish reverse SSH tunnels, deploy remote-access software for persistent interactive access, and supports C2-issued commands. The malware uses PyArmor Pro obfuscation, silent execution, a lock-file mechanism, selective file scanning/exfiltration, and embedded networking functions to hinder detection and reverse engineering.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.