
⚠️ Armored Likho targeted power and government agencies. Kaspersky says the attacks span Russia, Brazil, and Kazakhstan, using BusySnake Stealer, GitHub-hosted payloads, Go2Tunnel reverse tunneling, and patched CVE-2025-9491 LNK abuse. How the stealer chain works: https://thehackernews.com/2026/07/armored-likho-targets-government.html
Post summary
The text reports that Armored Likho actors are actively exploiting CVE-2025-9491 via LNK abuse across multiple countries, with the vulnerability already patched by vendors.



