Armored Likho
Russia-attributed (Kaspersky — moderate confidence) · Espionage / credential theft targeting government and critical infrastructure
Tactics, Techniques & Procedures (TTPs)
- Spear-phishing via NSIS-packaged executable droppers and LNK shortcut files exploiting ZDI-CAN-25373 (executes embedded payload on shortcut open)
- BusySnake infostealer: Python-based credential harvester targeting Chrome/Firefox/Edge saved passwords, cookies, Telegram sessions, RDP credentials, and cryptocurrency wallet files
- In-memory execution variant of BusySnake — second-generation build eliminates all disk artefacts, defeating signature-based endpoint detection
- Go2Tunnel reverse SSH proxy for C2 persistence through firewalls and NAT boundaries
- AquilaRAT loader deployment alongside BusySnake for secondary access
- AI-assisted code generation patterns in loader tooling — emoji bullet-point comments embedded in code blocks, consistent with LLM-generated development assistance
- Fast-flux C2 infrastructure: winupdate[.]live, arvax[.]xyz, varenie[.]live domain cluster with reverse SSH tunneling
Known Targets
Analyst Notes
Documented by Kaspersky in July 2026. Armored Likho shares tooling (Go2Tunnel, AquilaRAT) with the Awaken Likho / Core Werewolf cluster, suggesting either a common developer or operator overlap. The geographic targeting — Russia, Kazakhstan, Brazil — is unusual for a Russia-attributed group; the inclusion of Russian and Kazakh government agencies may indicate an internal intelligence collection mandate (targeting partners or domestic agencies) rather than purely adversarial foreign operations. The in-memory BusySnake variant represents a significant capability upgrade — the absence of on-disk indicators defeats most enterprise endpoint detection tools that rely on file scanning rather than memory analysis.
Also Known As