Meet BusySnake: The Stealthy Malware Quietly Raiding Government Networks

A newly discovered hacking group is hitting government offices and critical services across three countries with a capable piece of spy software. Here is what it does and who is at risk.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a government office desk at night, lit only by a monitor's cold blue glow
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Kaspersky identified a previously unknown hacking group called "Armored Likho" targeting government agencies and critical infrastructure organisations in Russia, Brazil and Kazakhstan.
  • The group's main weapon is a custom spy tool, "BusySnake Stealer", capable of lifting browser passwords, cookies, cryptographic keys and Telegram session data from infected machines.
  • Armored Likho delivered fake emails disguised as official government or social-assistance documents to trick staff into opening malicious files.
  • Kaspersky found coding patterns suggesting the group used large language models to generate early-stage malware components.
  • Kaspersky has published indicators of compromise that organisations can use to check whether BusySnake is already on their systems.

A hacking group nobody had documented before has been quietly breaking into government computers and critical-service networks, carrying off credentials and cryptographic keys (the digital codes that protect sensitive data). The group, known to Kaspersky researchers as "Armored Likho", was first reported by Dark Reading. We first covered the group on 3 July 2026, when Kaspersky noted it mixes espionage against institutions with money-driven attacks on individuals.

How did the hackers actually get in?

Victims received a spear-phishing email, a highly personalised fake message crafted to look like official correspondence. Lures included psychological assessments or humanitarian-aid applications. Opening the attachment produced a convincing decoy document. In the background, hidden software was already installing itself.

The final payload is BusySnake Stealer, written in Python. It collects browser-stored passwords, clipboard contents (anything copied but not yet pasted), Telegram login sessions and authentication data (the information an app uses to confirm your identity). It can also open a reverse SSH tunnel, giving attackers ongoing remote access long after the initial compromise. A command-and-control channel lets them push further instructions as needed.

Should you worry about detection?

Detecting BusySnake isn't straightforward. Kaspersky found the malware uses the commercial tool PyArmor Pro to encrypt its own code, decrypting each function only for the instant it needs to run before re-encrypting immediately. It runs without opening a visible window. It embeds networking functions directly in its own code rather than relying on external tools. Each of those choices is deliberate: together they push the malware well outside what generic security scanners handle easily.

One detail is worth sitting with. Kaspersky says coding style in the early-stage loader components suggests the attackers used large language models to generate them. Redundant comments and unnecessary code blocks are a recognised side-effect of AI-generated code. Kaspersky says this lets the group "broaden its available attack vectors." It's a meaningful shift: groups with modest coding skills can now produce polished attack tools faster than before. We've tracked the AI-generated malware trend since 6 July 2026 across three stories.

Kaspersky hasn't linked Armored Likho to any specific government or nation state.

If you work in a government office or an organisation handling public services, the practical steps are straightforward. Don't open attachments from unexpected emails, even apparently official ones. Report anything suspicious to your IT or security team. Multi-factor authentication (confirming your identity via a separate device) won't stop BusySnake once it's installed, but it limits how far stolen passwords alone can travel.

The bigger picture: Armored Likho is patient, technically maturing and building long-term access rather than smashing and grabbing. That's the profile to watch.

© 2026 Threat Vectr