{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:17:30.298Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-armored-likho-spear-phishing-targets-government-and-power-sector-in-thre","title":"Armored Likho spear phishing targets government and power sector in three countries","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Government agencies and electric power organisations in Russia, Brazil and Kazakhstan","sector":"Government","country":"Russia","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Espionage","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Armored Likho (overlaps with Eagle Werewolf)","summary":"Kaspersky reported in July 2026 on Armored Likho, a group targeting government agencies and the electric power sector in Russia, Brazil and Kazakhstan with spear-phishing emails. Lures referenced official government notices and social programmes and carried RAR archives containing executables. The chain pulled payloads from GitHub, exploited CVE-2025-9491 in Windows LNK handling, and deployed BusySnake Stealer, AquilaRAT, Go2Tunnel and RustDesk.","how_it_worked":"The entry point was a document a civil servant would plausibly be expected to open: a notice about an official government matter or a social programme, delivered as a RAR attachment. AquilaRAT was disguised as a Starlink device checklist, borrowing the credibility of equipment the target's organisation actually uses. Opening the archive and running its contents started the chain; the LNK vulnerability then carried execution forward without further user action. BusySnake harvested clipboard data, files, screenshots, cryptocurrency wallets, Telegram credentials and browser cookies, while RustDesk and reverse SSH tunnels held remote access open.","lessons":"Blocking executable content inside archives at the mail gateway and patching the LNK handling flaw removes both halves of the chain; the lure only works if the attachment can run.","confidence":"Confirmed","sources":[{"title":"Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer","url":"https://thehackernews.com/2026/07/armored-likho-targets-government.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-armored-likho-spear-phishing-targets-government-and-power-sector-in-thre"}]}