Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Armored Likho Tool Compromises Telegram & Records Conversations

Armored Likho Tool Compromises Telegram & Records Conversations

Posted on August 13, 2026 By CWS

Armored Likho’s Latest Cyber Threat

A cyber-espionage campaign attributed to Armored Likho has been using a deceptive donation application to target individuals and organizations within Russia. This malicious app, once executed, installs software that can hijack Telegram accounts and eavesdrop on conversations without the user’s knowledge.

The significance of this operation lies in its dual threat: accessing account information while simultaneously enabling audio surveillance. This breach can lead to the exposure of chat histories, files, contacts, and verbal discussions, posing severe risks to privacy and organizational security.

How the Toolkit Operates

The strategy employed by Armored Likho is not a typical smash-and-grab but a prolonged surveillance effort, allowing the attackers to build comprehensive intelligence on their targets. This ongoing access can significantly amplify the damage, especially for those handling sensitive data or critical projects.

According to Securelist, which shared its findings with Cyber Security News, the campaign was identified in May 2026. Researchers discovered the Rust-based Still Toolkit while investigating attacks on various sectors, including private and governmental institutions in Russia. Victims are lured in by software masquerading as a charity service, which conceals its true malicious intent.

Technical Aspects of the Still Toolkit

The primary component, Still Sync, targets Telegram Desktop session data, allowing attackers to exploit authenticated accounts. This method bypasses the need for login credentials, demonstrating the vulnerabilities associated with cloned Telegram sessions. Once access is gained, the toolkit can extract account details, private chats, and media files, transforming a single device breach into a significant intelligence gathering operation.

The malware registers the infected device with a command server and awaits instructions to activate its data collection features. It can search through both standard and portable Telegram data locations, and even attempt alternative methods if direct access is denied. This process circumvents typical password phishing tactics by leveraging existing session proofs.

Implications of Audio Surveillance

Beyond data theft, the Still Audio module adds a layer of surveillance by monitoring microphones. It starts recording when sound exceeds a certain level, converting the audio to MP3 and sending it to the attackers. Although it operates in the background, it does not fully hide microphone usage, offering a clue for incident responders.

This module can also adapt by changing server addresses if the primary connection is lost, showcasing a resilience similar to ClickFix malware chains. The campaign’s connection to Armored Likho, also known as Eagle Werewolf, is evidenced by similarities in code and infrastructure with previous operations.

For those who have installed suspicious apps, immediate action is crucial. Disconnect affected devices from networks, preserve evidence, and consult a trusted security team. It is also advised to review Telegram sessions, terminate unauthorized access, and reset passwords from a secure device.

Organizations are urged to block indicators of compromise, investigate related activity, and promptly inform affected parties. The threat underlines the importance of deploying live intelligence from global security operations centers to preempt phishing and malware threats.

Cyber Security News Tags:Armored Likho, cyber espionage, cybersecurity news, data privacy, malware toolkit, microphone surveillance, phishing threats, privacy breach, Rust malware, Telegram security

Post navigation

Previous Post: Jewelbug Exploits Browsers to Infiltrate Government Systems
Next Post: Fortinet Addresses Critical Security Flaws in Key Products

Related Posts

PCPJack Malware Targets Cloud Services for Credential Theft PCPJack Malware Targets Cloud Services for Credential Theft Cyber Security News
OpenAI Delays GPT-5.6 Amid U.S. Government Concerns OpenAI Delays GPT-5.6 Amid U.S. Government Concerns Cyber Security News
Highly Sophisticated macOS DigitStealer Employs Multi-Stage Attacks to Evade detection Highly Sophisticated macOS DigitStealer Employs Multi-Stage Attacks to Evade detection Cyber Security News
CISA Issues Alert on Exploited cPanel Vulnerability CISA Issues Alert on Exploited cPanel Vulnerability Cyber Security News
Salesforce Issues Alert on ShinyHunters Threat to Experience Cloud Salesforce Issues Alert on ShinyHunters Threat to Experience Cloud Cyber Security News
OpenClaw 2026.2.23 Enhances AI Security and Features OpenClaw 2026.2.23 Enhances AI Security and Features Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fortinet Addresses Critical Security Flaws in Key Products
  • Armored Likho Tool Compromises Telegram & Records Conversations
  • Jewelbug Exploits Browsers to Infiltrate Government Systems
  • North Korean IT Workers Exploit AI and Remote Access
  • Data Breach at ShipMonk Risks Trezor Customer Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fortinet Addresses Critical Security Flaws in Key Products
  • Armored Likho Tool Compromises Telegram & Records Conversations
  • Jewelbug Exploits Browsers to Infiltrate Government Systems
  • North Korean IT Workers Exploit AI and Remote Access
  • Data Breach at ShipMonk Risks Trezor Customer Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark