Kaspersky uncovers new APT Armored Likho using AI-written loader and BusySnake stealer against government and power-sector targets
Security teams defending power grids and government networks have a new problem: Kaspersky says a newly identified APT group, Armored Likho, is deploying an AI-written loader alongside a Python infostealer called BusySnake, hitting targets in Russia, Brazil and Kazakhstan.
Kaspersky has documented a previously unreported hacking group it calls Armored Likho, running spear-phishing campaigns against government agencies and the electric power sector in Russia, Brazil and Kazakhstan. The group's toolkit combines a new Python infostealer named BusySnake, built to lift browser passwords and cookies, Telegram desktop sessions, clipboard contents, screenshots and cryptocurrency wallet keys, with a first-stage loader that shows clear signs of having been written with a large language model: verbose inline comments, emoji bullet points in the source, and redundant code blocks. Two details matter for anyone defending critical infrastructure. First, the loader's AI fingerprints suggest the effort required to produce functional intrusion code is dropping, while those same artifacts give defenders a way to spot it. Second, the initial access relies on a Windows shortcut (LNK) flaw, CVE-2025-9491, that Microsoft $MSFT already fixed in its November 2025 updates. That means the campaign is largely reaching organizations that never applied an eight-month-old patch. The infection chain leans on social engineering too, including a fake psychological survey used as a decoy to lower a victim's guard. Source: Kaspersky Securelist.