
ARMORED Likho has launched a new phishing campaign that uses AI‑generated lures to deliver the BusySnake Stealer malware to government agencies and electric power operators in Russia, Brazil and Kazakhstan according to recent reporting.
The BusySnake Stealer is a Python‑based information harvester that extracts browser passwords, cookies and cryptocurrency wallet data while hiding its activity through process‑name spoofing and code obfuscation as noted by analysts.
Infection starts with a spear‑phishing email that carries a seemingly benign archive; when opened it runs a script that downloads and executes the stealer, which also deploys a remote access trojan and a tunnelling tool to maintain reverse SSH connections for data exfiltration researchers explain.
Kaspersky telemetry shows the activity began in early July 2026 and continues, with victims identified in critical‑infrastructure networks and overlaps noted with the Eagle Werewolf group, suggesting a shared toolkit or collaboration according to telemetry.
Defenders should scrutinise inbound mail for executable or LNK attachments, enable sandbox detonation for unknown files and hunt for indicators such as the SHA256 hash of the BusySnake loader and periodic HTTPS beacons to domains linked to the group advisories recommend.
Organisations are advised to restrict PowerShell and command‑line usage, apply network segmentation between corporate and OT environments and refresh staff training on recognizing sophisticated phishing that incorporates AI‑crafted text experts warn.