Three countries. Government ministries and electric utility operators. One Python-based stealer built with AI-generated loaders that most signature-based tools never flagged. That’s the shape of Armored Likho, a previously undocumented threat actor Kaspersky just attributed to a campaign spanning Russia, Brazil, and Kazakhstan, hitting the power sector alongside state agencies. This is what modern cybersecurity teams are actually up against right now: not a flashy zero-day, but a patient spear-phishing operation that slipped a stealer called BusySnake past defenses built for yesterday’s malware.

The power sector isn’t a soft target by accident. Utility operators run legacy control systems that can’t always take an EDR agent, staff who click attachments because their job requires opening unfamiliar files from vendors, and IT teams stretched across both corporate and operational networks. Armored Likho found the seam and walked through it.
It Looks Like Commodity Crime, So Analysts Wave It Through
Here’s the part that should worry every SOC analyst triaging alerts by gut feel: Armored Likho doesn’t behave like a nation-state actor is supposed to. Kaspersky described the group’s approach directly.
“Armored Likho blends financially motivated campaigns targeting private individuals with targeted cyber espionage aimed at organizations,” Kaspersky said in its technical analysis.
That blending is the whole point. A stealer that also hits random consumers looks like noise, the kind of low-priority alert that gets closed without a second look. Meanwhile the same toolkit, pointed at a government network or a power utility, is doing reconnaissance and credential theft that feeds something much bigger. Threat detection built around “known APT infrastructure equals high severity, commodity malware equals low severity” misses exactly this pattern, because the classification itself is the deception.
It’s not an isolated tactic either. Malwarebytes reported this week on a verified X ad distributing Mac malware and a separate ConsentFix campaign harvesting Microsoft accounts through malicious OAuth consent prompts, not exploits. Different targets, same underlying shift: attackers are increasingly betting on social engineering and identity theft over the software vulnerabilities your patch cycle is built to catch. When the entry point is a person clicking “allow” instead of a CVE, your firewall never gets a vote.
AI-Generated Loaders Mean Your Hash List Expires Overnight
The other detail in the Armored Likho reporting that deserves more attention than it’s getting: the loaders delivering BusySnake are AI-generated. That’s not a marketing flourish in the writeup, it’s an operational problem. Static signatures and known-bad hash lists work when a malware family stays roughly the same across a campaign. AI-assisted generation means each loader variant can be structurally different enough to dodge hash matching while behaving identically once it executes.

This is why threat-protection strategies leaning entirely on indicators of compromise are running out of runway. If the file changes every campaign but the behavior doesn’t, security hardening has to shift from “block the known bad file” to “block the known bad action,” things like a script interpreter spawning network connections it has no business making, or a document macro reaching out to an unfamiliar domain. That’s a harder engineering problem than updating a blocklist, but it’s the only approach that holds up against loaders built to be unique on every delivery.
What Actually Reduces the Blast Radius Here
None of this requires exotic tooling. It requires treating spear-phishing against critical infrastructure as the standing threat it is, not a once-a-year tabletop exercise topic.
- Segment operational technology and power management systems from the corporate network entirely, so a compromised email account in finance can’t reach turbine controls.
- Lock down script interpreters (PowerShell, Python, WSH) with execution policies and application control, since a Python-based stealer needs an interpreter to run somewhere it shouldn’t.
- Shift detection logic toward behavior over hashes: unusual parent-child process chains, unexpected outbound connections from office documents, credential access attempts outside normal hours.
- Rate-limit and monitor authentication attempts on remote access and VPN gateways; brute-force attempts against exposed logins remain a cheap, reliable way in even when phishing fails.
- Restrict OAuth app consent for your tenant so users can’t grant a malicious app the same access ConsentFix relies on to steal Microsoft accounts.
- Build defense in depth around email specifically: attachment sandboxing, link rewriting, and a reporting workflow employees actually use, because spear-phishing is still the initial access method doing the most damage this quarter.
The incident response side matters just as much as prevention. If Armored Likho or something like it does land in your environment, the difference between a contained incident and a multi-week cleanup is whether your team can answer “what did this touch” within hours, not days. That means centralized, off-host logging for anything touching OT-adjacent systems, a rehearsed isolation procedure for compromised endpoints, and clear authority to pull a segment offline without waiting for a committee to sign off. Power sector operators in particular should already have this drilled, because the cost of getting it wrong isn’t a data breach notification letter. It’s an outage.
Threat actors like Armored Likho aren’t succeeding because their tools are unbreakable. They’re succeeding because they’ve correctly bet that most organizations still triage by malware family instead of by behavior, and still treat spear-phishing as a training slide instead of an engineering problem. Fix the second part and the first part stops mattering nearly as much.
Sources
- Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
- Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign
- Verified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
