BusySnake Stealer is a Python-based infostealer associated with the Armored Likho threat actor, also linked by some researchers to Eagle Werewolf. It has been used in campaigns targeting primarily government agencies and the electric power sector in Russia, Kazakhstan, and Brazil, while related activity also indicates financially motivated targeting of individuals. The malware is heavily obfuscated with PyArmor and runs silently as a background Python process on Windows systems.
BusySnake Stealer is designed for broad information theft and follow-on operator access. Reported capabilities include theft of browser-stored passwords and cookies from Chromium-based browsers and Firefox, collection of Telegram session data, harvesting of one-time-password secrets and cryptocurrency wallet material, clipboard monitoring, screenshot capture, file-system inventorying, and exfiltration of selected user documents. Multiple reports also describe command execution, reverse SSH tunneling, and the ability to deploy or abuse remote-access software to maintain interactive access. Newer variants add a task-management framework, delayed execution for anti-analysis, stealthier scheduled-task creation, and in-memory execution of arbitrary Python scripts fetched from command-and-control infrastructure.
Observed delivery has relied on spearphishing emails carrying archive files that contain either NSIS-based droppers or malicious Windows shortcut files. In documented campaigns, the shortcut-based chain abused CVE-2025-9491 to conceal command-line execution and launch obfuscated PowerShell, ultimately deploying BusySnake Stealer. The malware establishes persistence on Windows through scheduled tasks, including variants that use VBScript launchers or COM-based task registration.
BusySnake Stealer appears to be part of Armored Likho's modular toolkit alongside other remote-access and tunneling components such as Go2Tunnel, and its architecture has been noted to overlap with AquilaRAT. The malware reflects an evolution from pure credential and data theft toward combined espionage, remote access, and post-compromise operator enablement on victim Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
An Armored Likho campaign that used a malicious shortcut to abuse CVE-2025-9491, execute obfuscated PowerShell, and deploy BusySnake Stealer. | An Armored Likho campaign used a malicious shortcut to abuse CVE-2025-9491, execute obfuscated PowerShell, and deploy BusySnake Stealer.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Похожим образом Armored Likho загружала на устройство BusySnake Stealer в более ранней кампании.
BusySnake Stealer — Fonctionnalités principales # L’infostealer est écrit en Python , obfusqué et chiffré via PyArmor Pro 9.2.0 , et s’exécute sans fenêtre console (extension .pyw ).
33 distinct techniques documented for this family, organized by ATT&CK tactic.
It runs without opening a visible console window and uses scheduled tasks to remain active. In newer samples, the malware creates scheduled tasks through Windows component interfaces instead of directly calling standard task commands, a change intended to reduce detection.
Armored Likho campaign that used a malicious shortcut to abuse CVE-2025-9491, execute obfuscated PowerShell, and deploy BusySnake Stealer.
A second path uses a malicious LNK shortcut that hides its command-line activity through spaces and line breaks. The shortcut launches an obfuscated command and PowerShell process
Il est persisté via une tâche planifiée (toutes les 5 minutes) créée par un script VBScript ( run.vbs ).
L’infostealer est écrit en Python ... le script get-pip.py , et le payload principal module.pyw ... Exécution de scripts Python arbitraires en mémoire sans écriture disque
It runs without opening a visible console window and uses scheduled tasks to remain active. In newer samples, the malware creates scheduled tasks through Windows component interfaces instead of directly calling standard task commands, a change intended to reduce detection.
T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
It runs without opening a visible console window and uses scheduled tasks to remain active. In newer samples, the malware creates scheduled tasks through Windows component interfaces instead of directly calling standard task commands, a change intended to reduce detection.
The executable launches a fake survey, then injects malicious code into another process and retrieves additional payloads from online repositories.
T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
BusySnake is protected with code obfuscation and encryption that only decrypts functions when needed.
The executable launches a fake survey, then injects malicious code into another process and retrieves additional payloads from online repositories.
The stealer can also decrypt saved passwords from Chromium-based browsers and Firefox profiles, extract browser cookies
Recherche de secrets 2FA (pattern otpauth:// ) ... Recherche de wallets crypto (fichiers JSON)
After execution, BusySnake inventories files, watches the clipboard, searches for long hexadecimal keys, and collects documents from Desktop, Documents, and Downloads folders.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Its remote-control features include reverse SSH tunneling, which can give operators a route back into a compromised system even after the initial theft activity.
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ранее использовавшийся группировкой Armored Likho стилер, упомянутый как предшествующий инструмент и для сравнения с цепочками доставки BusySnake RAT.
Stealer malware deployed via a malicious Windows shortcut.
Information-stealing malware deployed in an Armored Likho campaign after abuse of CVE-2025-9491 and PowerShell execution.
Python-based infostealer used in an active campaign attributed with medium confidence to Armored Likho. It steals browser passwords and cookies, logs clipboard activity, inventories files, exfiltrates documents, captures screenshots, steals Telegram data, searches for 2FA secrets and crypto wallets, and can deploy RustDesk for remote control. It also supports reverse SSH tunneling and newer variants can execute arbitrary Python scripts in memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.