Research government agencies armored likho ics-ot-iot power sector russia
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
CVE Tools coverage
Security researchers attribute a campaign by the threat actor Armored Likho to attacks against government organizations and the electric power sector in Russia, Brazil, and Kazakhstan. The activity includes spear-phishing and malware that deploys BusySnake Stealer, a Python-based information stealer for Windows that can exfiltrate browser data (including cookies), screenshots, clipboard contents, and other sensitive material. The intrusion chain also leverages a Windows shortcut-related flaw, tracked as CVE-2025-9491 (aka ZDI-CAN-25373) and patched by Microsoft in November 2025, enabling remote code execution when LNK files are handled improperly.