What happened
A newly identified threat group dubbed Armored Likho has been conducting dual-purpose campaigns — blending opportunistic financial attacks on private individuals with targeted espionage against government bodies and electric utilities in Russia, Brazil, and Kazakhstan. The group deploys a credential-harvesting tool called BusySnake to extract sensitive data from compromised systems, according to a technical report from Kaspersky. Separately, the FBI coordinated with industry partners to seize hundreds of domains tied to NetNut, a residential proxy service operated by publicly traded Israeli firm Alarum Technologies. The action followed reporting by Krebs on Security that linked NetNut's infrastructure to a botnet called Popa, which was quietly routing malicious traffic through unwitting users' devices.
Why it matters for your business
The Armored Likho campaign illustrates how threat actors now routinely combine mass-market phishing with precision espionage, meaning organizations in adjacent sectors — energy suppliers, government contractors, and regional utilities — face elevated risk even if they are not the primary target. BusySnake's credential-theft capability means compromised employee accounts can serve as persistent entry points into enterprise networks long after initial infection. The NetNut seizure carries a different but equally urgent lesson: commercial proxy services, even those listed on major stock exchanges, can be co-opted as botnet relay infrastructure without operators' apparent awareness. Security and procurement teams should audit any third-party network services — VPNs, proxy layers, traffic routing tools — for exposure to compromised residential IP pools that could mask attacker activity or implicate corporate infrastructure in illicit traffic flows.
What to watch next
Kaspersky's ongoing analysis of Armored Likho suggests the group's tooling is still evolving, and attribution to a broader threat cluster has not yet been confirmed publicly, meaning further disclosures about targets and techniques are likely. On the law enforcement side, the NetNut seizure raises questions about Alarum Technologies' regulatory standing and whether additional proxy platforms tied to the Popa botnet remain operational. Businesses relying on residential proxy services for legitimate use cases — ad verification, market research, localization testing — should monitor for fresh FBI or CISA guidance on vetting provider legitimacy.
