APT group Armored Likho deploys BusySnake Stealer, a new Python-based infostealer hitting government and electric power targets across Russia

, Kazakhstan

, and Brazil

, with LLM-generated loaders complicating attribution.
- Initial access uses spear-phishing archives (ZIPs/RARs with names like "psihologicheskiy_test.zip" or "zayavka_gumanitarnayapomosch.rar") dropping either NSIS-based EXE droppers or LNK files exploiting ZDI-CAN-25373 to hide PowerShell commands. Both chains stage into AppData\WindowsHelper, drop a Python 3.12 runtime, and persist via a scheduled task named WindowsHelper firing every 5 minutes. First-stage loaders contain verbose comments and emoji, strongly indicating LLM generation (T1566.001, T1059.001, T1053.005).
- BusySnake Stealer (module.pyw, protected by PyArmor Pro 9.2.0) harvests clipboard data, enumerates files for 64-char hex keys, exfiltrates Desktop/Documents/Downloads files under 5 MB, steals Chromium passwords via DPAPI, decrypts Firefox credentials via PK11SDR_Decrypt without master password re-auth, and grabs Telegram tdata by force-killing telegram.exe. It also deploys a browser extension for cookie theft and establishes reverse SSH tunnels using keys from C2.
An inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil.
securelist.com