BusySnake is a Python-based Windows infostealer associated with the threat actor Armored Likho, also known as Eagle Werewolf. It has been used in spearphishing campaigns targeting government agencies and organizations in the electric power sector, with confirmed victimology in Russia, Kazakhstan, and Brazil. The activity has been assessed as supporting both credential-focused financially motivated operations and cyber-espionage objectives.
BusySnake is delivered through phishing emails carrying malicious archives that contain either executable droppers or weaponized Windows shortcut files. Observed lures impersonate official notices, humanitarian aid requests, social programs, debt-related themes, and psychological tests. The infection chain uses staged loaders, decoy documents, obfuscated PowerShell, and downloaded Python components. Some first-stage loaders have been assessed as likely AI-assisted due to distinctive coding artifacts.
Once installed, BusySnake operates covertly in the background, using obfuscation and on-demand decryption to hinder analysis. It establishes persistence via scheduled tasks, including newer variants that create tasks through Windows component interfaces to reduce detection. The malware steals passwords and cookies from Chromium-based browsers and Firefox, collects clipboard contents, captures screenshots, inventories and exfiltrates user documents, searches for one-time-password secrets, and steals Telegram session data and cryptocurrency-related material. Reported variants also support command execution, in-memory execution of arbitrary Python scripts, installation of remote administration software, and reverse SSH tunneling for persistent operator access and follow-on surveillance. Structural and operational similarities have also been noted with AquilaRAT-era tooling used by the same actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...затем заражают Windows-системы новым стилером BusySnake... На зараженной машине стилер похищает данные из буфера обмена, делает скриншоты, собирает пользовательские документы, а также извлекает пароли и файлы cookie из Firefox и браузеров на базе Chromium... BusySnake способен развернуть обратный SSH-туннель, установить RustDesk для удаленного управления системой и запускать произвольные Python-скрипты прямо в памяти.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Armored Likho deployed the BusySnake stealer to harvest browser credentials, cookies, documents, screen information, and reverse SSH tunnels.
Armored Likho has launched a phishing campaign that uses AI-generated loaders to deploy the newly identified BusySnake Stealer.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Вредонос закрепляется в системе через запланированную задачу, которая запускает его каждые пять минут.
Both use comparable C2 endpoints to report task execution and register scheduled tasks that pose as legitimate Microsoft utilities. AquilaRAT uses MicrosoftOfficeUpdate, while BusySnake Stealer uses WindowsHelper.
researchers linked it to earlier activity involving AquilaRAT... Both use comparable C2 endpoints to report task execution
Вредонос закрепляется в системе через запланированную задачу, которая запускает его каждые пять минут.
Вредонос закрепляется в системе через запланированную задачу, которая запускает его каждые пять минут.
Both use comparable C2 endpoints to report task execution and register scheduled tasks that pose as legitimate Microsoft utilities. AquilaRAT uses MicrosoftOfficeUpdate, while BusySnake Stealer uses WindowsHelper.
Impact & Control: This diverse stack enables them to maintain stealthy host control, exfiltrate credentials, and deploy tailored modules.
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer used to harvest browser credentials, cookies, documents, and screen information, and to enable reverse SSH tunnels.
BusySnake is a newly identified stealer used after spear-phishing infection chains. It steals browser credentials, cookies, clipboard data, local documents, screenshots, cryptocurrency-related data, Telegram session files, and one-time password secrets; it also supports operator commands, scheduled-task persistence, code obfuscation/encryption, and reverse SSH tunneling for continued access.
Related: 'BusySnake' Infostealer Slithers Into Critical Infrastructure Networks
A Python-based infostealer used in spear-phishing campaigns to steal credentials, sensitive documents, clipboard contents, browser cookies, Telegram session tokens, screenshots, 2FA secrets, and cryptocurrency wallet data. It also supports reverse SSH tunneling for persistent remote access and manual file theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.