INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

BusySnake Infostealer Infects Critical Infrastructure

| 2026-07-06 21:37 CRITICAL MEDIUM DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
A previously unknown advanced persistent threat (APT) group, tracked by researchers at Kaspersky as "Armored Likho," has been targeting government agencies and critical infrastructure organizations in multiple countries with a sophisticated malware toolkit designed to steal credentials, sensitive documents, and other high-value data. The attacks have claimed victims in Russia, Brazil, and Kazakhstan since late June 2026, when DomainTools warned of Iran-, Russia-, and China-backed groups systematically targeting water management systems in perceived adversaries. Armored Likho's campaign uses spear-phishing emails masquerading as official government communications or social assistance communications to launch the attacks, which include both financially motivated campaigns targeted at individuals and cyber-espionage operations against organizations; the final stage payload is a Python-based infostealer dubbed "BusySnake Stealer" capable of harvesting sensitive information from victim systems.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign KasperskyCampaign Kaspersky Volt TyphoonVolt Typhoon SnakeSnake
Target & Sectors
NORTH_AMERICA NORTH_AMERICA CENTRAL_ASIA CENTRAL_ASIA governmentgovernment
Incident Timeline
‎2026/07/06
Kaspersky discovered emails containing archive files with malicious executables or Windows shortcut files disguised as documents to target victims in Russia, Brazil, and Kazakhstan.
threat_actor Volt Typhoon
infrastructure Windows
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Intelligence Sources