HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

AI‑Generated Malware Fuels “Armored Likho” APT Campaign Targeting Governments and Power Grids

Kaspersky uncovered a new APT group, Armored Likho, that leverages AI‑generated, obfuscated malware delivered through spear‑phishing and a known LNK shortcut vulnerability to compromise government agencies and electric‑utility operators in Russia, Kazakhstan, and Brazil. The campaign highlights gaps in security‑awareness training and endpoint monitoring that SOC 2 programs must address.

LiveThreat™ Intelligence · 📅 July 07, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
2 recommended
📰
Source
securityaffairs.com

AI‑Generated Malware Fuels “Armored Likho” APT Campaign Targeting Governments and Power Grids

What Happened — Kaspersky researchers identified a new APT group, “Armored Likho,” that uses AI‑generated, heavily obfuscated malware (modular RATs, the BusySnake Python infostealer, and Go2Tunnel) delivered via spear‑phishing emails and a ZDI‑CAN‑25373 LNK shortcut vulnerability. The campaign is aimed at government agencies and electric‑utility operators in Russia, Kazakhstan, and Brazil, with a parallel financially‑motivated track against private individuals.

Why It Matters for Compliance & Audit Readiness

  • Spear‑phishing and LNK‑based execution bypass traditional perimeter controls, highlighting the need for documented Security Awareness Training and phishing‑simulation programs that satisfy SOC 2 CC6.1 (Security) and CC6.2 (Risk Management).
  • The AI‑generated payloads are deliberately crafted to evade dynamic analysis, underscoring the importance of continuous monitoring of endpoint detection controls and evidence collection for audit‑ready incident‑response processes.

Who Is Affected — Government & public‑sector entities, electric‑utility operators, and any organization with high‑value intellectual property or critical‑infrastructure exposure.

Recommended Actions

  • Map the phishing vector to SOC 2 CC6.1 controls; update your security‑awareness curriculum to include AI‑generated malware indicators and LNK shortcut abuse.
  • Deploy endpoint telemetry that captures execution of NSIS self‑extractors and PowerShell‑based loaders; retain logs as audit evidence of control effectiveness.

Source: Security Affairs – AI‑Generated Malware Powers New Armored Likho APT Campaign

Technical Notes

  • Attack vector: spear‑phishing emails with malicious NSIS archives or LNK shortcuts exploiting ZDI‑CAN‑25373.
  • Malware stack: obfuscated Go and Python RATs, BusySnake Stealer (Python 3.12), Go2Tunnel tunneling tool.
  • No public CVE for the custom loader; the LNK exploit is tracked as ZDI‑CAN‑25373.
📰 Original Source
https://securityaffairs.com/194854/apt/ai-generated-malware-powers-new-armored-likho-apt-campaign.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →