Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
Researchgovernment agenciesarmored likhopower sectorOur summary
Security researchers attribute a campaign by the threat actor Armored Likho to attacks against government organizations and the electric power sector in Russia, Brazil, and Kazakhstan. The activity includes spear-phishing and malware that deploys BusySnake Stealer, a Python-based information stealer for Windows that can exfiltrate browser data (including cookies), screenshots, clipboard contents, and other sensitive material. The intrusion chain also leverages a Windows shortcut-related flaw, tracked as CVE-2025-9491 (aka ZDI-CAN-25373) and patched by Microsoft in November 2025, enabling remote code execution when LNK files are handled improperly.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.