Skip to content
NetarxImpact Database
Spear Phishing (Email)No AI reportedConfirmedCampaign

Armored Likho spear phishing targets government and power sector in three countries

Government agencies and electric power organisations in Russia, Brazil and Kazakhstan · Government · Russia · July 2026

What happened

Kaspersky reported in July 2026 on Armored Likho, a group targeting government agencies and the electric power sector in Russia, Brazil and Kazakhstan with spear-phishing emails. Lures referenced official government notices and social programmes and carried RAR archives containing executables. The chain pulled payloads from GitHub, exploited CVE-2025-9491 in Windows LNK handling, and deployed BusySnake Stealer, AquilaRAT, Go2Tunnel and RustDesk.

How the deception worked

The entry point was a document a civil servant would plausibly be expected to open: a notice about an official government matter or a social programme, delivered as a RAR attachment. AquilaRAT was disguised as a Starlink device checklist, borrowing the credibility of equipment the target's organisation actually uses. Opening the archive and running its contents started the chain; the LNK vulnerability then carried execution forward without further user action. BusySnake harvested clipboard data, files, screenshots, cryptocurrency wallets, Telegram credentials and browser cookies, while RustDesk and reverse SSH tunnels held remote access open.

The control that would have caught it· our reading, not a claim from the sources

Blocking executable content inside archives at the mail gateway and patching the LNK handling flaw removes both halves of the chain; the lure only works if the attachment can run.

Sources (1)

  1. Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
    The Hacker News·thehackernews.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.