Armored Likho: Attack on Government and Energy via BusySnake Stealer

Colleagues, I’d like to draw attention to a cybersecurity development.
This is a clear example of how Armored Likho targets government agencies and the energy sector through BusySnake Stealer.
Key points:
• initial access via spear-phishing and archives containing malicious EXEs;
• payload delivery from GitHub;
• an alternative chain uses LNK files and the already patched CVE-2025-9491;
• persistence through VBScript and scheduled tasks.
According to the analysis, the stealer can steal cookies, passwords, screenshots, Telegram data and crypto wallet information, and can also operate via a reverse SSH tunnel.
Why it matters: the campaign combines espionage, data theft and persistent system access.
How do you defend against scenarios like this in your environment?
#cybersecurity #infosec #threatintel #phishing

