August 22, 2026
- Armored Likho has rewritten BusySnake in Golang and adopted the open-source Kharon RAT, while moving C2 and payload hosting off public GitHub to private GitLab and GitHub repos to frustrate analysis and blend with normal developer traffic. LLM-generated loaders remain part of their toolchain (@blackorbird) (earlier coverage).
· Threat Activity
in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight
August 15, 2026
- Armored Likho expanded its espionage toolkit with a Rust/Tauri dropper fronted by a fake catalog, plus "Still Sync" for Telegram data theft and "Still Audio" for voice surveillance, targeting Russian users (Securelist).
· Threat Activity
in A Heavy Day for Exploit Research and In-the-Wild N-Days
July 5, 2026
- Armored Likho targets government and electric-power organizations across Russia, Brazil, and Kazakhstan with the BusySnake stealer, blending financially motivated activity with espionage. The Hacker News
· Threat Activity
in Confidential Computing's Root of Trust May Be Unfixable
July 4, 2026
- Armored Likho deploys BusySnake Stealer. Kaspersky attributed a global, Python-based obfuscated malware campaign — blending financially motivated and espionage activity — to government and power-sector targets in Russia, Brazil, and Kazakhstan. Securelist
· Threat Intelligence
in Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat