What happened
Kaspersky reported in July 2026 on Armored Likho, a group targeting government agencies and the electric power sector in Russia, Brazil and Kazakhstan with spear-phishing emails. Lures referenced official government notices and social programmes and carried RAR archives containing executables. The chain pulled payloads from GitHub, exploited CVE-2025-9491 in Windows LNK handling, and deployed BusySnake Stealer, AquilaRAT, Go2Tunnel and RustDesk.
How the deception worked
The entry point was a document a civil servant would plausibly be expected to open: a notice about an official government matter or a social programme, delivered as a RAR attachment. AquilaRAT was disguised as a Starlink device checklist, borrowing the credibility of equipment the target's organisation actually uses. Opening the archive and running its contents started the chain; the LNK vulnerability then carried execution forward without further user action. BusySnake harvested clipboard data, files, screenshots, cryptocurrency wallets, Telegram credentials and browser cookies, while RustDesk and reverse SSH tunnels held remote access open.
The control that would have caught it· our reading, not a claim from the sources
Blocking executable content inside archives at the mail gateway and patching the LNK handling flaw removes both halves of the chain; the lure only works if the attachment can run.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.