Armored Likho Group Strengthens Cyber-Espionage Tactics with Advanced Still Toolkit

Date:

Armored Likho Group Strengthens Cyber-Espionage Tactics with Advanced Still Toolkit

In May 2026, a significant cyber-espionage campaign linked to the Armored Likho group, also known as Eagle Werewolf, was revealed. This operation is targeting a diverse array of private individuals and organizations across multiple sectors in Russia, including major corporations, the public sector, IT, and educational institutions. The attackers have employed a deceptive application that poses as a donation service to ensnare victims. However, the most critical aspect of this campaign is not the initial infection method but rather the advanced malicious implants used for cyber-espionage. Findings from Kaspersky’s research team provide detailed insights into these developments.

The Armored Likho group has a history of involvement in various cyber-attacks, with recent activities showing considerable overlap with earlier campaigns from February and November 2024. The current operation marks a notable expansion of their toolkit, introducing new capabilities that significantly enhance their espionage efforts.

New Cyber-Espionage Toolkit: The Still Toolkit

At the heart of this campaign is the newly identified Still Toolkit, developed using the Rust programming language. This toolkit consists of two primary components: Still Sync and Still Audio. Still Sync is specifically designed to extract Telegram session data, enabling attackers to maintain continuous access to victims’ accounts. By utilizing the Telegram API, the attackers can automatically gather chat logs, media files, and other sensitive information.

The second component, Still Audio, serves a distinct purpose: it facilitates covert audio surveillance. This implant analyzes incoming audio streams, detects speech, records conversations, and transmits these recordings to a command-and-control (C2) server. The technical sophistication of these tools underscores the evolving nature of cyber-espionage tactics employed by the Armored Likho group.

Initial Infection Method

The infection process initiates with the distribution of a counterfeit application that mimics a donation service. While the precise distribution method remains unclear, several samples posing as legitimate applications from various Russian foundations have been identified. Upon launching the app, users are presented with a login form requesting a password, likely supplied by the attackers. After entering a valid password, users are shown a catalog of items available for donation, while the dropper silently decrypts and executes the payload in the background.

Technical Details of Still Sync

Still Sync functions as an asynchronous application, leveraging the Tokio library for its architecture. It communicates with the C2 server via gRPC and utilizes FlatBuffers for message serialization. The implant collects essential system information, including motherboard serial number, CPU ID, and BIOS serial number, which it hashes and sends to the C2 server for registration.

Once registered, Still Sync can execute various commands based on settings retrieved from the server, including the capability to extract Telegram data. The module searches for the tdata folder, which contains session data, and can employ multiple methods to access this information, even bypassing standard access controls if necessary.

Capabilities of Still Audio

Still Audio parallels the functionality of Still Sync but is focused on audio surveillance. Upon launch, it extracts a library for encoding audio data and registers with the C2 server. The implant employs a Voice Activity Detection (VAD) algorithm to determine when to start and stop recording based on audio levels. Notably, it does not attempt to conceal its presence, appearing in Windows settings under the name “Intel Audio.” Recorded audio is encoded and sent to the C2 server for further analysis.

Infrastructure and Victims

The infrastructure supporting this campaign is varied, utilizing multiple hosting providers and domains to complicate detection efforts. The primary targets of this campaign are users in Russia, focusing on private individuals, corporate entities, government organizations, IT companies, and educational institutions.

For further details on this threat and indicators of compromise, refer to the comprehensive report by Kaspersky. Source: cyberwarriorsmiddleeast.com

For ongoing coverage and breaking updates, visit our Latest News section.

Published on 2026-08-13 15:16:00 • By the Editorial Desk

Share post:

Subscribe

Popular

More like this
Related

Dubai Accelerates Workforce Development Through Essential AI Literacy Programs

Dubai Accelerates Workforce Development Through Essential AI Literacy Programs AI...

UAE Strengthens Defense Against Coordinated Cyberattacks Targeting Critical Infrastructure

UAE Strengthens Defense Against Coordinated Cyberattacks Targeting Critical Infrastructure Recent...

Snowflake Breach: Hacker Pleads Guilty, Compromising Over 100 Million Records

Snowflake Breach: Hacker Pleads Guilty, Compromising Over 100 Million...