Skip to content
← All Threat Actors
Nation-State high Russia (assessed)

Armored Likho

Russia-attributed (Kaspersky — moderate confidence) · Espionage / credential theft targeting government and critical infrastructure

Reports 1
Active Since 2024
Last Reported 6 Jul 2026
Sectors Targeted critical-infrastructure, ot-ics, government

Tactics, Techniques & Procedures (TTPs)

  • Spear-phishing via NSIS-packaged executable droppers and LNK shortcut files exploiting ZDI-CAN-25373 (executes embedded payload on shortcut open)
  • BusySnake infostealer: Python-based credential harvester targeting Chrome/Firefox/Edge saved passwords, cookies, Telegram sessions, RDP credentials, and cryptocurrency wallet files
  • In-memory execution variant of BusySnake — second-generation build eliminates all disk artefacts, defeating signature-based endpoint detection
  • Go2Tunnel reverse SSH proxy for C2 persistence through firewalls and NAT boundaries
  • AquilaRAT loader deployment alongside BusySnake for secondary access
  • AI-assisted code generation patterns in loader tooling — emoji bullet-point comments embedded in code blocks, consistent with LLM-generated development assistance
  • Fast-flux C2 infrastructure: winupdate[.]live, arvax[.]xyz, varenie[.]live domain cluster with reverse SSH tunneling

Known Targets

Russian government agenciesKazakhstan government organisationsBrazilian government entitiesElectric power sector operators (Russia, Kazakhstan)Critical infrastructure across the former Soviet space

Analyst Notes

Documented by Kaspersky in July 2026. Armored Likho shares tooling (Go2Tunnel, AquilaRAT) with the Awaken Likho / Core Werewolf cluster, suggesting either a common developer or operator overlap. The geographic targeting — Russia, Kazakhstan, Brazil — is unusual for a Russia-attributed group; the inclusion of Russian and Kazakh government agencies may indicate an internal intelligence collection mandate (targeting partners or domestic agencies) rather than purely adversarial foreign operations. The in-memory BusySnake variant represents a significant capability upgrade — the absence of on-disk indicators defeats most enterprise endpoint detection tools that rely on file scanning rather than memory analysis.

Also Known As

Eagle WerewolfAwaken Likho (shared tooling overlap)Core Werewolf (shared infrastructure)