LIVE · cybersecurity feed
Live wire
security

Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer

A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. "Armored Likho blends financially motivate

zeroday.news · 29d ago

A newly identified threat actor, dubbed Armored Likho, has been linked to cyberattacks impacting government entities and the electric power sector in Russia, Brazil, and Kazakhstan. This group appears to combine financially motivated tactics with espionage objectives, according to cybersecurity researchers.

The threat actor's operations have been observed utilizing a custom malware strain referred to as BusySnake Stealer. This malware is designed to exfiltrate sensitive information from compromised systems.

Armored Likho's targeting strategy suggests a focus on organizations that handle critical infrastructure or hold significant governmental data. The geographical distribution of these attacks across multiple countries indicates a potentially broad operational scope.

The BusySnake Stealer malware is capable of gathering various types of data, including credentials, system information, and potentially other sensitive files. Its primary function is to facilitate the theft of this information for the benefit of the threat actor.

While the exact motivations behind Armored Likho's activities are still under investigation, the blend of financial and espionage-related objectives points towards a sophisticated and multi-faceted adversary. Such actors often aim to gain access to valuable data for financial gain, intelligence gathering, or to disrupt critical operations.

The specific methods used by Armored Likho to gain initial access to target networks have not been detailed. However, common vectors for such attacks often include phishing campaigns, exploitation of unpatched vulnerabilities, or the use of compromised credentials.

The cybersecurity community is actively monitoring Armored Likho's activities to better understand their tactics, techniques, and procedures (TTPs). This ongoing analysis is crucial for developing effective defense strategies against this emerging threat.

Organizations within the government and energy sectors, particularly those located in or connected to Russia, Brazil, and Kazakhstan, are advised to review and enhance their security postures. This includes implementing robust endpoint detection and response solutions, ensuring all systems are up-to-date with security patches, and conducting regular security awareness training for employees to mitigate risks associated with phishing and social engineering.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.