<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/busysnake-stealer-slithers-into-critical-infrastructure-networks-dcqwywayo" -->

---
title: BusySnake Stealer Slithers into Critical Infrastructure...
description: Kaspersky researchers have uncovered a previously unknown APT group called &#x27;Armored Likho&#x27; targeting government agencies and critical infrastructure...
canonical: https://daily.dev/posts/busysnake-stealer-slithers-into-critical-infrastructure-networks-dcqwywayo
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: BusySnake Stealer Slithers into Critical Infrastructure Networks | daily.dev
og:description: Kaspersky researchers have uncovered a previously unknown APT group called &#x27;Armored Likho&#x27; targeting government agencies and critical infrastructure...
og:url: https://daily.dev/posts/busysnake-stealer-slithers-into-critical-infrastructure-networks-dcqwywayo
og:image: https://api.daily.dev/og/posts/dcqwYWaYO.png
og:image:alt: BusySnake Stealer Slithers into Critical Infrastructure Networks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# BusySnake Stealer Slithers into Critical Infrastructure Networks

**[Dark Reading](https://daily.dev/sources/dr)** · 5 min read · 0 upvotes · 0 comments

## Summary

Kaspersky researchers have uncovered a previously unknown APT group called 'Armored Likho' targeting government agencies and critical infrastructure organizations in Russia, Brazil, and Kazakhstan. The group uses spear-phishing emails disguised as official government communications to deliver a multi-stage malware chain. The final payload is a Python-based infostealer dubbed 'BusySnake Stealer,' capable of harvesting browser credentials, cookies, clipboard data, cryptographic keys, and Telegram session data. It can also establish reverse SSH tunnels and deploy remote-access software for persistent access. BusySnake employs PyArmor Pro for bytecode encryption, modular architecture, and embedded networking functions to evade detection and complicate reverse engineering. Kaspersky notes the group appears to be using LLMs to generate first-stage payloads, broadening its attack vectors. The campaign fits a broader trend of state-affiliated APTs targeting critical infrastructure for espionage and sabotage.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.darkreading.com/cyberattacks-data-breaches/busysnake-infostealer-critical-infrastructure-networks>

## Similar posts on daily.dev

- [Armored Likho's new weapon: BusySnake Stealer](https://daily.dev/posts/armored-likho-s-new-weapon-busysnake-stealer-jlglbr4ad) · Securelist · 0 upvotes · 0 comments
- [Operation HumanitarianBait: An Infostealer Campaign](https://daily.dev/posts/operation-humanitarianbait-an-infostealer-campaign-mxpu5wjgr) · Cyble · 0 upvotes · 0 comments
- [New Armored Likho tools target Telegram and eavesdropping](https://daily.dev/posts/new-armored-likho-tools-target-telegram-and-eavesdropping-xtg4q18ob) · Securelist · 0 upvotes · 0 comments

---

Tags: [#python](https://daily.dev/tags/python), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/busysnake-stealer-slithers-into-critical-infrastructure-networks-dcqwywayo)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"BusySnake Stealer Slithers into Critical Infrastructure Networks","url":"https://daily.dev/posts/busysnake-stealer-slithers-into-critical-infrastructure-networks-dcqwywayo","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/busysnake-stealer-slithers-into-critical-infrastructure-networks-dcqwywayo"},"datePublished":"2026-07-06T21:52:02.575Z","dateModified":"2026-07-06T21:52:29.920Z","description":"Kaspersky researchers have uncovered a previously unknown APT group called 'Armored Likho' targeting government agencies and critical infrastructure...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/81b46afe652568ebbcde4a930a207aae?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/81b46afe652568ebbcde4a930a207aae?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Dark Reading","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Dark Reading","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/dr","url":"https://daily.dev/sources/dr"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/busysnake-stealer-slithers-into-critical-infrastructure-networks-dcqwywayo","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"python,malware","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Dark Reading","item":"https://daily.dev/sources/dr"},{"@type":"ListItem","position":3,"name":"BusySnake Stealer Slithers into Critical Infrastructure Networks"}]}
```

