Armored Likho: the newly-named hacking crew hitting power grids and government offices

Russian security firm Kaspersky says the group mixes espionage against big institutions with money-driven attacks on ordinary people.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A high-voltage electricity substation at dusk, transformers and steel pylons silhouetted against a deep blue sky, faint control-room glow visible through a dist
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Kaspersky named a previously unknown hacking group called Armored Likho in a technical report published this week.
  • The group has attacked government agencies and electric power companies across Russia, Kazakhstan and two other countries.
  • Armored Likho mixes two goals in one operation: spying on organisations and stealing money from private individuals.
  • The crew deploys a stealer called BusySnake to grab passwords and files from infected machines.

There's a new name on the board, and it's earned a second look.

Russian antivirus company Kaspersky says it has been tracking a hacking group nobody had publicly documented before, calling them Armored Likho. A report published this week says the crew has broken into government offices and electricity companies across Russia, Kazakhstan and Brazil.

What makes this group unusual isn't the tools. It's the mix of motives.

Most hacking crews pick a lane: money or espionage. Armored Likho, according to Kaspersky, runs both at the same time. "Armored Likho blends financially motivated campaigns targeting private individuals with targeted cyber espionage aimed at organizations," the company said in its technical analysis.

Who is being hit, and what are the hackers after?

The targets split into two distinct groups. On one side are government departments and electric power firms, the kind of places a spy agency wants a foothold inside. On the other are private individuals, whose bank logins and personal files can be sold or drained directly.

Kaspersky says the group deploys a malicious program called BusySnake. It's what the industry calls a stealer: software that quietly copies passwords saved in your browser and cryptocurrency wallet files, then ships them back to the attackers. Stealers aren't new. They're the crowbar of the modern criminal underground. What matters here is who's holding the crowbar and where they're pointing it.

The electric power angle is worth flagging alongside our 3 July report on three unpatched flaws in Schneider Electric grid protection gear: the sector is drawing attention from multiple directions at once.

Why does this matter to ordinary people?

If you work for a government body or an energy company in one of the targeted countries, your security team should already be reading Kaspersky's write-up. That's their job today.

For everyone else, the concern is familiar. A stealer on your home computer will empty a savings account or hand over your email password to whoever pays for it. Infection routes are almost always the same ones: a booby-trapped attachment, a cracked software download from a shady site, or a fake login page in a convincing email.

Turn on two-factor authentication, the second code your bank or email sends to your phone, on anything that holds money or personal data. That one step defeats most stolen passwords.

Should you trust the attribution?

Carefully, and no more.

Armored Likho is a fresh label. Kaspersky is the outfit naming it, and Kaspersky is a Russian company reporting on attacks that include Russian victims. That's not a reason to dismiss the research. It's a reason to wait for a second firm to examine the same samples and either agree or push back.

Naming a new group is the easy part. Proving the same hands are behind every attack listed under that name takes months of patient work.

For now, treat Armored Likho as a useful working category. A crew worth watching. Not yet a household name in the way Lazarus or Sandworm are, but the kind of operation that becomes one if the reporting holds up.

© 2026 Threat Vectr