[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2RT6z11-GpwTGx2nIz7YlA8luW7R4YRNVDKoozFmWHk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"6e554b2d-bc0c-49ce-b2b2-43f3490803da","armored-likho-apt-uses-spear-phishing-to-target-critical-infrastructure","0054c353-fa25-4d13-92ee-db476f9012ec","Armored Likho APT Uses Spear-Phishing to Target Critical Infrastructure","The Armored Likho APT group is successfully compromising government and electric power organizations by exploiting the human attack surface through targeted spear-phishing emails containing weaponized archives and LNK files. Once inside, their modular malware toolkit enables credential theft, persistent remote access, and OTP key scraping — a combination that can bypass multi-factor authentication and entrench attackers deeply within critical infrastructure networks. The targeting of electric power entities raises the stakes considerably, as successful intrusions could disrupt essential services affecting entire populations. The overlap with Eagle Werewolf activity suggests a well-resourced, coordinated threat ecosystem that learns and adapts, making one-time defenses insufficient.","**Immediate actions:**\n- Deploy advanced email filtering and sandboxing to detain weaponized archives and LNK files before they reach end users.\n- Enforce hardware-based MFA (e.g., FIDO2 keys) to neutralize OTP-scraping malware that targets software-based authenticators.\n- Block execution of LNK, script, and archive files from untrusted locations via application allowlisting or GPO policies.\n\n**Long-term improvements:**\n- Conduct regular, role-tailored spear-phishing simulation training for employees in government and critical infrastructure roles.\n- Implement least-privilege access controls and privileged access workstations (PAWs) to limit the blast radius of credential theft.\n- Establish network segmentation between corporate IT and operational technology (OT) environments to prevent lateral movement into critical systems.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) solutions capable of identifying Python and Go-based malware execution anomalies.\n- Monitor for unusual outbound tunneling activity (e.g., Go2Tunnel) using network traffic analysis and DNS inspection tools.\n- Centralize and correlate logs from endpoints, email gateways, and network devices in a SIEM to detect multi-stage APT kill chains early.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"CIS Control 9 – Email and Web Browser Protections","CIS Control 6 – Access Control Management","CIS Control 13 – Network Monitoring and Defense","CIS Control 14 – Security Awareness and Skills Training","CIS Control 16 – Application Software Security","NIST SP 800-53 AC-6 – Least Privilege","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST SP 800-53 SC-7 – Boundary Protection","NIST SP 800-53 AT-2 – Literacy Training and Awareness","NIST SP 800-53 AU-6 – Audit Record Review and Reporting","MITRE ATT&CK T1566 – Phishing (Spear-phishing Attachment)","MITRE ATT&CK T1555 – Credentials from Password Stores","IEC 62443 – Industrial Automation and Control Systems Security","published","2026-07-06T16:20:42.548841+00:00","2026-07-06T16:20:42.237+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fwww.securityweek.com\u002Farmored-likho-apt-targeting-government-electric-power-entities\u002F","armored-likho-apt-targeting-government-electric-power-entities-97f22e","Armored Likho APT Targeting Government, Electric Power Entities",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":40,"name":41,"slug":42,"description":43,"color":44},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":46,"name":47,"slug":48,"description":49,"color":50},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[52],{"id":53,"date":54,"edition":55,"title":56,"audio_url":57},"1467af35-090a-4b1d-bf6d-74aaf64d808c","2026-07-07","morning","ThreatNoir Morning Brief — July 7","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-07\u002Fthreatnoir-morning-brief-2026-07-07.mp3"]