Armored Likho’s Latest Cyber Threat
A cyber-espionage campaign attributed to Armored Likho has been using a deceptive donation application to target individuals and organizations within Russia. This malicious app, once executed, installs software that can hijack Telegram accounts and eavesdrop on conversations without the user’s knowledge.
The significance of this operation lies in its dual threat: accessing account information while simultaneously enabling audio surveillance. This breach can lead to the exposure of chat histories, files, contacts, and verbal discussions, posing severe risks to privacy and organizational security.
How the Toolkit Operates
The strategy employed by Armored Likho is not a typical smash-and-grab but a prolonged surveillance effort, allowing the attackers to build comprehensive intelligence on their targets. This ongoing access can significantly amplify the damage, especially for those handling sensitive data or critical projects.
According to Securelist, which shared its findings with Cyber Security News, the campaign was identified in May 2026. Researchers discovered the Rust-based Still Toolkit while investigating attacks on various sectors, including private and governmental institutions in Russia. Victims are lured in by software masquerading as a charity service, which conceals its true malicious intent.
Technical Aspects of the Still Toolkit
The primary component, Still Sync, targets Telegram Desktop session data, allowing attackers to exploit authenticated accounts. This method bypasses the need for login credentials, demonstrating the vulnerabilities associated with cloned Telegram sessions. Once access is gained, the toolkit can extract account details, private chats, and media files, transforming a single device breach into a significant intelligence gathering operation.
The malware registers the infected device with a command server and awaits instructions to activate its data collection features. It can search through both standard and portable Telegram data locations, and even attempt alternative methods if direct access is denied. This process circumvents typical password phishing tactics by leveraging existing session proofs.
Implications of Audio Surveillance
Beyond data theft, the Still Audio module adds a layer of surveillance by monitoring microphones. It starts recording when sound exceeds a certain level, converting the audio to MP3 and sending it to the attackers. Although it operates in the background, it does not fully hide microphone usage, offering a clue for incident responders.
This module can also adapt by changing server addresses if the primary connection is lost, showcasing a resilience similar to ClickFix malware chains. The campaign’s connection to Armored Likho, also known as Eagle Werewolf, is evidenced by similarities in code and infrastructure with previous operations.
For those who have installed suspicious apps, immediate action is crucial. Disconnect affected devices from networks, preserve evidence, and consult a trusted security team. It is also advised to review Telegram sessions, terminate unauthorized access, and reset passwords from a secure device.
Organizations are urged to block indicators of compromise, investigate related activity, and promptly inform affected parties. The threat underlines the importance of deploying live intelligence from global security operations centers to preempt phishing and malware threats.
