Kaspersky researchers have uncovered an active APT campaign by a group dubbed Armored Likho (also known as Eagle Werewolf), targeting government agencies and electric power sectors in Russia, Kazakhstan, and Brazil. The group deploys a newly documented Python-based infostealer called BusySnake Stealer, delivered via spear-phishing emails with malicious EXE or LNK attachments. First-stage loaders are AI-generated, complicating attribution. BusySnake Stealer is obfuscated with PyArmor Pro, runs persistently via scheduled tasks, and features clipboard logging, file system enumeration, browser credential and cookie theft (Chromium and Firefox), screenshot capture, 2FA secret scraping, Telegram session harvesting, cryptocurrency wallet search, and reverse SSH tunneling. A newer version adds stealthier persistence via COM objects, in-memory Python script execution, and a task-management framework with status tracking. The malware shares architectural overlaps with AquilaRAT and Go2Tunnel, tools previously attributed to the same group. IoCs including file hashes and C2 domains are provided.