BusySnake is a Python-based Windows infostealer associated with the Armored Likho threat actor, also known as Eagle Werewolf. It has been used in spearphishing campaigns targeting government agencies and organizations in the electric power sector, with observed victimology in Russia, Kazakhstan, and Brazil. The activity has been assessed as supporting both credential-focused financially motivated operations and longer-term espionage-oriented access.
BusySnake is delivered through phishing emails carrying malicious archives that contain either executable droppers or weaponized Windows shortcut files. Observed lures impersonate official notices, humanitarian aid themes, social programs, debt-related documents, and psychological tests. Infection chains use staged loaders, decoy content, PowerShell, and downloaded Python components to install the stealer while reducing user suspicion.
On compromised hosts, BusySnake operates in the background, uses obfuscation and protected Python bytecode, and establishes persistence via scheduled tasks. Reported collection behavior includes theft of browser passwords and cookies from Chromium-based browsers and Firefox, clipboard monitoring, screenshot capture, collection of user documents, harvesting of Telegram session data, scraping of one-time-password secrets, and searching for cryptocurrency-related data. The malware also inventories files and selectively collects data from common user directories.
Beyond theft, BusySnake supports post-compromise operator control. Documented capabilities include receiving commands from command-and-control infrastructure, opening reverse SSH tunnels for persistent remote access, installing RustDesk for remote administration, and executing arbitrary Python scripts directly in memory. Its feature set indicates use not only as a stealer but also as a lightweight access platform for continued surveillance and targeted follow-on activity.
BusySnake has been linked by researchers to earlier tooling associated with Armored Likho, including similarities to AquilaRAT-style task handling and the incorporation of reverse tunneling functionality previously seen as a separate utility. The malware remains under active development, with operators refining delivery, persistence, and evasion techniques.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...затем заражают Windows-системы новым стилером BusySnake... На зараженной машине стилер похищает данные из буфера обмена, делает скриншоты, собирает пользовательские документы, а также извлекает пароли и файлы cookie из Firefox и браузеров на базе Chromium... BusySnake способен развернуть обратный SSH-туннель, установить RustDesk для удаленного управления системой и запускать произвольные Python-скрипты прямо в памяти.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Armored Likho has launched a phishing campaign that uses AI-generated loaders to deploy the newly identified BusySnake Stealer.
Armored Likho has launched a phishing campaign that uses AI-generated loaders to deploy the newly identified BusySnake Stealer.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Вредонос закрепляется в системе через запланированную задачу, которая запускает его каждые пять минут.
Both use comparable C2 endpoints to report task execution and register scheduled tasks that pose as legitimate Microsoft utilities. AquilaRAT uses MicrosoftOfficeUpdate, while BusySnake Stealer uses WindowsHelper.
researchers linked it to earlier activity involving AquilaRAT... Both use comparable C2 endpoints to report task execution
Вредонос закрепляется в системе через запланированную задачу, которая запускает его каждые пять минут.
Вредонос закрепляется в системе через запланированную задачу, которая запускает его каждые пять минут.
Both use comparable C2 endpoints to report task execution and register scheduled tasks that pose as legitimate Microsoft utilities. AquilaRAT uses MicrosoftOfficeUpdate, while BusySnake Stealer uses WindowsHelper.
Impact & Control: This diverse stack enables them to maintain stealthy host control, exfiltrate credentials, and deploy tailored modules.
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BusySnake is a newly identified stealer used after spear-phishing infection chains. It steals browser credentials, cookies, clipboard data, local documents, screenshots, cryptocurrency-related data, Telegram session files, and one-time password secrets; it also supports operator commands, scheduled-task persistence, code obfuscation/encryption, and reverse SSH tunneling for continued access.
Related: 'BusySnake' Infostealer Slithers Into Critical Infrastructure Networks
A Python-based infostealer used in spear-phishing campaigns to steal credentials, sensitive documents, clipboard contents, browser cookies, Telegram session tokens, screenshots, 2FA secrets, and cryptocurrency wallet data. It also supports reverse SSH tunneling for persistent remote access and manual file theft.
Python-based stealer used in phishing campaigns against government and electric power organizations. It persists via a scheduled task, steals clipboard data, screenshots, documents, browser passwords and cookies, OTP secrets, cryptocurrency wallet files, and Telegram tdata, and can also receive commands from C2 to open reverse SSH tunnels, install RustDesk, and execute in-memory Python scripts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.