Activity timeline
Armored Likho appears in 3 tracked threats between and .
ATT&CK techniques observed
- T1005 Data from Local System — Collectionobserved in 3 of 3 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 3 tracked threats
- T1053.005 Scheduled Task — Persistenceobserved in 3 of 3 tracked threats
- T1055 Process Injection — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
- T1059.001 PowerShell — Executionobserved in 3 of 3 tracked threats
- T1059.006 Python — Executionobserved in 3 of 3 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 3 of 3 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1113 Screen Capture — Collectionobserved in 3 of 3 tracked threats
- T1115 Clipboard Data — Collectionobserved in 3 of 3 tracked threats
- T1204.002 User Execution: Malicious File — Executionobserved in 3 of 3 tracked threats
- T1218.011 Rundll32 — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
- T1539 Steal Web Session Cookie — Credential Accessobserved in 3 of 3 tracked threats
- T1555.003 Credentials from Web Browsers — Credential Accessobserved in 3 of 3 tracked threats
Tracked threats
- Armored Likho APT (Eagle Werewolf) Deploys AI-Generated Loaders to Drop BusySnake Python Stealer Against Government and Power-Sector TargetsHIGH
- Armored Likho APT Targets Government and Power Sector with New BusySnake Stealer via CVE-2025-9491 LNK AbuseHIGH
- Armored Likho APT Deploys BusySnake Python Stealer with PyArmor Obfuscation Against Government and Power Infrastructure TargetsHIGH