Kaspersky says Armored Likho is targeting government and electric power organizations in Russia, Brazil, and Kazakhstan

A newly identified hacking group called Armored Likho has been targeting government and electric power organizations in multiple countries, while also running financially motivated attacks against individuals. Kaspersky says the actor uses spear-phishing emails with executable or shortcut (LNK) files to install malware including the Python-based BusySnake Stealer and Go2Tunnel, enabling credential theft, browser cookie and password extraction, Telegram session theft, screenshot capture, reverse SSH tunnels, and persistent remote access.
Why it matters: Government and energy organizations are high-value targets, and the campaign uses common email lures that can reach many users. Defenders should harden email filtering, block malicious LNK/executable attachments, monitor for GitHub-hosted payload retrieval and reverse SSH activity, and hunt for BusySnake, Go2Tunnel, and related persistence mechanisms.

Sources

Armored Likho APT Targeting Government, Electric Power Entities
Ionut Arghire 2026.07.06 100% relevant
This article appears to be the first tracked report establishing Armored Likho as a distinct threat actor, naming its targets, countries, malware set, and initial access methods.
← Back to all stories