Armored Likho APT Uses Spear-Phishing to Target Critical Infrastructure
The Armored Likho APT group is successfully compromising government and electric power organizations by exploiting the human attack surface through targeted spear-phishing emails containing weaponized archives and LNK files. Once inside, their modular malware toolkit enables credential theft, persistent remote access, and OTP key scraping — a combination that can bypass multi-factor authentication and entrench attackers deeply within critical infrastructure networks. The targeting of electric power entities raises the stakes considerably, as successful intrusions could disrupt essential services affecting entire populations. The overlap with Eagle Werewolf activity suggests a well-resourced, coordinated threat ecosystem that learns and adapts, making one-time defenses insufficient.
Tactical Insight
Immediate actions
- Deploy advanced email filtering and sandboxing to detain weaponized archives and LNK files before they reach end users.
- Enforce hardware-based MFA (e.g., FIDO2 keys) to neutralize OTP-scraping malware that targets software-based authenticators.
- Block execution of LNK, script, and archive files from untrusted locations via application allowlisting or GPO policies.
Long-term improvements
- Conduct regular, role-tailored spear-phishing simulation training for employees in government and critical infrastructure roles.
- Implement least-privilege access controls and privileged access workstations (PAWs) to limit the blast radius of credential theft.
- Establish network segmentation between corporate IT and operational technology (OT) environments to prevent lateral movement into critical systems.
Detection measures
- Deploy endpoint detection and response (EDR) solutions capable of identifying Python and Go-based malware execution anomalies.
- Monitor for unusual outbound tunneling activity (e.g., Go2Tunnel) using network traffic analysis and DNS inspection tools.
- Centralize and correlate logs from endpoints, email gateways, and network devices in a SIEM to detect multi-stage APT kill chains early.