BusySnake Stealer is a Python-based Windows infostealer associated with campaigns attributed with medium confidence to the Armored Likho threat actor, also linked by some reporting to Eagle Werewolf. It has been used primarily against government agencies and electric power organizations in Russia, Kazakhstan, and Brazil, while also appearing in financially motivated operations against individuals. The malware is heavily obfuscated with PyArmor and runs silently as a background Python process without a visible console window.
BusySnake Stealer is modular and supports broad data-theft and follow-on access functions. Reported capabilities include theft of browser credentials from Chromium-based browsers and Firefox, browser cookie collection, clipboard monitoring, screenshot capture, file-system inventorying, document collection and exfiltration, Telegram session theft, discovery of one-time-password secrets, and searches for cryptocurrency wallet material and other cryptographic keys. It also supports command-driven execution of additional tasks from command-and-control infrastructure, including in newer variants the in-memory execution of arbitrary Python scripts.
The malware establishes persistence on infected hosts through scheduled tasks, with newer variants using COM-based task creation for stealth. It incorporates anti-analysis measures such as delayed execution and uses locking logic to avoid multiple concurrent instances. BusySnake Stealer also provides remote-access-enabling functionality through reverse SSH tunneling and can deploy or interact with RustDesk to facilitate persistent operator access.
Observed delivery chains rely on spear-phishing emails carrying archive files that contain either NSIS-based droppers or malicious Windows shortcut files. In documented campaigns, the shortcut-based chain abused CVE-2025-9491 and launched obfuscated PowerShell before staging the Python payload and its runtime components. Architectural and functional overlaps with tools such as Go2Tunnel and AquilaRAT have been cited in attribution assessments tying the malware to Armored Likho’s broader toolkit.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
An Armored Likho campaign that used a malicious shortcut to abuse CVE-2025-9491, execute obfuscated PowerShell, and deploy BusySnake Stealer. | An Armored Likho campaign used a malicious shortcut to abuse CVE-2025-9491, execute obfuscated PowerShell, and deploy BusySnake Stealer.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Armored Likho used a malicious Windows shortcut to deploy BusySnake Stealer;
BusySnake Stealer — Fonctionnalités principales # L’infostealer est écrit en Python , obfusqué et chiffré via PyArmor Pro 9.2.0 , et s’exécute sans fenêtre console (extension .pyw ).
33 distinct techniques documented for this family, organized by ATT&CK tactic.
It runs without opening a visible console window and uses scheduled tasks to remain active. In newer samples, the malware creates scheduled tasks through Windows component interfaces instead of directly calling standard task commands, a change intended to reduce detection.
Armored Likho campaign that used a malicious shortcut to abuse CVE-2025-9491, execute obfuscated PowerShell, and deploy BusySnake Stealer.
A second path uses a malicious LNK shortcut that hides its command-line activity through spaces and line breaks. The shortcut launches an obfuscated command and PowerShell process
Il est persisté via une tâche planifiée (toutes les 5 minutes) créée par un script VBScript ( run.vbs ).
L’infostealer est écrit en Python ... le script get-pip.py , et le payload principal module.pyw ... Exécution de scripts Python arbitraires en mémoire sans écriture disque
It runs without opening a visible console window and uses scheduled tasks to remain active. In newer samples, the malware creates scheduled tasks through Windows component interfaces instead of directly calling standard task commands, a change intended to reduce detection.
T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
It runs without opening a visible console window and uses scheduled tasks to remain active. In newer samples, the malware creates scheduled tasks through Windows component interfaces instead of directly calling standard task commands, a change intended to reduce detection.
The executable launches a fake survey, then injects malicious code into another process and retrieves additional payloads from online repositories.
T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
BusySnake is protected with code obfuscation and encryption that only decrypts functions when needed.
The executable launches a fake survey, then injects malicious code into another process and retrieves additional payloads from online repositories.
The stealer can also decrypt saved passwords from Chromium-based browsers and Firefox profiles, extract browser cookies
Recherche de secrets 2FA (pattern otpauth:// ) ... Recherche de wallets crypto (fichiers JSON)
After execution, BusySnake inventories files, watches the clipboard, searches for long hexadecimal keys, and collects documents from Desktop, Documents, and Downloads folders.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Its remote-control features include reverse SSH tunneling, which can give operators a route back into a compromised system even after the initial theft activity.
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer malware deployed via a malicious Windows shortcut.
Information-stealing malware deployed in an Armored Likho campaign after abuse of CVE-2025-9491 and PowerShell execution.
Python-based infostealer used in an active campaign attributed with medium confidence to Armored Likho. It steals browser passwords and cookies, logs clipboard activity, inventories files, exfiltrates documents, captures screenshots, steals Telegram data, searches for 2FA secrets and crypto wallets, and can deploy RustDesk for remote control. It also supports reverse SSH tunneling and newer variants can execute arbitrary Python scripts in memory.
A Python-based stealer used to exfiltrate credentials, cryptocurrency keys, API secrets, sensitive documents, Telegram session data, and RustDesk credentials; it also establishes reverse SSH tunnels for operator access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.