A threat actor called Armored Likho has been conducting cyber espionage and financially motivated attacks against government agencies and energy sector organisations in Russia, Brazil, and Kazakhstan, using spear-phishing emails as the initial entry point. The group deploys a newly discovered Python-based malware called BusySnake Stealer, which harvests credentials, browser cookies, keystrokes, cryptocurrency wallets, and Telegram data, while evading detection through dynamic bytecode encryption and obfuscation techniques. Kaspersky has linked Armored Likho to the previously tracked Eagle Werewolf cluster, noting the group is actively refining its toolkit — including integrating reverse SSH tunnelling directly into the stealer — and may be using AI tools to assist in generating its first-stage payloads.