Armored Likho has noticeably rebuilt its malicious arsenal and began using the new remote access Trojan BusySnake RAT, capable of working in Windows, Linux and macOS. Kaspersky experts discovered three versions of the malware at once and traced how the developers consistently changed the architecture and control channels: from Telegram-bots to GitLab and a fully rewritten version on Go. In parallel, the intruders began to use generative AI more actively after entering the victim's infrastructure.
In the first version of BusySnake RAT, the developers used Python, and the teams were transmitted through Telegram. After the launch, the Trojan determined the operating system and the name of the computer, fixed in the system and connected to the Telegram-bot. Any text message received from the operator could turn into a system command, the result of the execution was returned through the same channel. In Windows, the malware created the planned task, in macOS used launched, and in Linux added a task cron. The detailed technical device of the new versions was dismantled in the report Securelist.
The next version of BusySnake RAT was already without Telegram. Armored Likho moved the control of infected computers to GitLab and engaged CI/CD project variables to share commands and results. The Trojan checked every five seconds for a new task, and once a minute informed the operator about the availability of the infected car. Such a scheme allowed to control several devices through one project GitLab and at the same time mask malicious interaction under the appeal to the legitimate service.
The most recent option found by the developers completely rewritten on Go. The new version has received the means of bypassing AMSI and ETW, checking for the presence of the debugger and launch in an isolated environment, as well as its own fixing mechanism. The Trojan checks the amount of RAM and the peculiarities of the time of operations, after which it stops working when signs of the research environment are detected. The transition from Python to a compiled binary file also spared developers a large number of external dependencies and complicated the analysis of the malware.
BusySnake RAT was not the only replenishment of the arsenal. Researchers have discovered the new Armored Likho campaign with the open Trojan Kharon RAT. The attack begins with an HTA or BAT bootloader, after which the next stage hits the computer, deciphering the main payload using ChaCha20. Kharon RAT provides remote access to the system, allows you to run commands, implement code in processes, upload files to an infected computer and output data outward. For communication with the management infrastructure, RAT supports HTTPS and SMB, and the ability to change network profiles helps to make it difficult to detect by the characteristic features of traffic.
Armored Likho has changed the way malicious components are delivered. Previously, the group placed individual bootloaders in the public repositories of GitHub, and in the new campaigns switched to private repositories GitHub and GitLab with access over API tokens. The main components with this approach are loaded through the legitimate GitLab infrastructure, so the usual analysis of network calls becomes more complex.
The experts paid special attention to generative AI. In the previous campaign, the signs of large language models were found mainly in bootloaders and scripts intended for initial penetration. In the new set of samples, similar signs appeared already in the components used for further development of the attack. According to the researchers, Armored Likho uses LLM to create auxiliary utilities and payloads, automating part of the development of malware and simultaneously complicating attribution.
The group came into the field of view of Kaspersky in the summer of 2026. In the July study of BusySnake Stealer, experts described another Armored Likho tool, a Python styler for Windows, designed to steal passwords, cookies and organize remote access. Researchers with medium confidence associate Armored Likho with the activity of Eagle Werewolf. The Eagle Werewolf infrastructure has previously been involved in the SecurityLab investigation: group-related servers were used in attacks on state and industry organizations using fake Starlink pages and Telegram channels.
In the first version of BusySnake RAT, the developers used Python, and the teams were transmitted through Telegram. After the launch, the Trojan determined the operating system and the name of the computer, fixed in the system and connected to the Telegram-bot. Any text message received from the operator could turn into a system command, the result of the execution was returned through the same channel. In Windows, the malware created the planned task, in macOS used launched, and in Linux added a task cron. The detailed technical device of the new versions was dismantled in the report Securelist.
The next version of BusySnake RAT was already without Telegram. Armored Likho moved the control of infected computers to GitLab and engaged CI/CD project variables to share commands and results. The Trojan checked every five seconds for a new task, and once a minute informed the operator about the availability of the infected car. Such a scheme allowed to control several devices through one project GitLab and at the same time mask malicious interaction under the appeal to the legitimate service.
The most recent option found by the developers completely rewritten on Go. The new version has received the means of bypassing AMSI and ETW, checking for the presence of the debugger and launch in an isolated environment, as well as its own fixing mechanism. The Trojan checks the amount of RAM and the peculiarities of the time of operations, after which it stops working when signs of the research environment are detected. The transition from Python to a compiled binary file also spared developers a large number of external dependencies and complicated the analysis of the malware.
BusySnake RAT was not the only replenishment of the arsenal. Researchers have discovered the new Armored Likho campaign with the open Trojan Kharon RAT. The attack begins with an HTA or BAT bootloader, after which the next stage hits the computer, deciphering the main payload using ChaCha20. Kharon RAT provides remote access to the system, allows you to run commands, implement code in processes, upload files to an infected computer and output data outward. For communication with the management infrastructure, RAT supports HTTPS and SMB, and the ability to change network profiles helps to make it difficult to detect by the characteristic features of traffic.
Armored Likho has changed the way malicious components are delivered. Previously, the group placed individual bootloaders in the public repositories of GitHub, and in the new campaigns switched to private repositories GitHub and GitLab with access over API tokens. The main components with this approach are loaded through the legitimate GitLab infrastructure, so the usual analysis of network calls becomes more complex.
The experts paid special attention to generative AI. In the previous campaign, the signs of large language models were found mainly in bootloaders and scripts intended for initial penetration. In the new set of samples, similar signs appeared already in the components used for further development of the attack. According to the researchers, Armored Likho uses LLM to create auxiliary utilities and payloads, automating part of the development of malware and simultaneously complicating attribution.
The group came into the field of view of Kaspersky in the summer of 2026. In the July study of BusySnake Stealer, experts described another Armored Likho tool, a Python styler for Windows, designed to steal passwords, cookies and organize remote access. Researchers with medium confidence associate Armored Likho with the activity of Eagle Werewolf. The Eagle Werewolf infrastructure has previously been involved in the SecurityLab investigation: group-related servers were used in attacks on state and industry organizations using fake Starlink pages and Telegram channels.