spear phishing2 articles
BusySnake: The Python Stealer Quietly Targeting Governments and Power Grids
A threat actor called Armored Likho has been conducting cyber espionage and financially motivated attacks against government agencies and energy sector organisations in Russia, Brazil, and Kazakhstan, using spear-phishing emails as the initial entry point. The group deploys a newly discovered Python-based malware called BusySnake Stealer, which harvests credentials, browser cookies, keystrokes, cryptocurrency wallets, and Telegram data, while evading detection through dynamic bytecode encryption and obfuscation techniques. Kaspersky has linked Armored Likho to the previously tracked Eagle Werewolf cluster, noting the group is actively refining its toolkit — including integrating reverse SSH tunnelling directly into the stealer — and may be using AI tools to assist in generating its first-stage payloads.
Chinese Hackers Dressed as India's Tax Authority Are Deploying DcRAT on Finance Teams
A suspected China-linked threat group is targeting Indian taxpayers, tax professionals, and corporate finance teams through a spear-phishing campaign called Operation DragonReturn, which impersonates India's Income Tax Department. Victims are tricked into downloading a fake tax filing utility that deploys DcRAT, a remote access trojan capable of stealing sensitive data, taking screenshots, and exfiltrating information to remote servers. Infrastructure analysis points to Chinese-linked IP addresses and overlaps with the known cybercrime group Silver Fox, suggesting the campaign is a deliberate, sustained effort aimed at intelligence collection and data theft.