Armored Likho Expands Cyber-Espionage with New Rust Toolkit

Armored Likho Expands Cyber-Espionage with New Rust Toolkit

First seen 13 Aug 2026, 22:40 UTC SecurelistGbhackersattack.mitre.orgbi.zone 90% similarity 70.5

Article Content

Browse articles
ThreatCluster

In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and educational institutions. The attackers employed a fraudulent donation-service application as the initial infection vector. The campaign features a new Rust-based toolkit called the Still Toolkit, which includes components for hijacking Telegram sessions and conducting audio surveillance via compromised Windows devices. The Still Sync component steals Telegram session data, while Still Audio records conversations and transmits them to a command-and-control server. The malicious app masquerades as a legitimate donation service, deceiving users into providing access. Kaspersky products detect the threat as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic. This campaign shows significant overlap with previous Armored Likho activities documented in November 2024, February 2026, and July 2026. The distribution method for the fake app remains unknown as of this writing.

Key Points: • Armored Likho's new campaign targets various sectors in Russia using a fake donation app. • The Still Toolkit includes components for stealing Telegram data and conducting audio surveillance. • Kaspersky identifies the malware as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.

ThreatCluster AI How this analysis works

Timeline

2024-11-01
Armored Likho's previous campaign documented
The group was previously reported using malicious droppers disguised as documents related to Starlink.
Securelist
2026-02-01
Armored Likho's February campaign reported
The group continued its operations with similar tactics, targeting Russian entities with disguised applications.
Securelist
2026-05-01
New cyber-espionage campaign launched
Armored Likho initiated a campaign using a fraudulent donation app to target various sectors in Russia.
Gbhackers
2026-08-13
Current campaign details published
Securelist and Gbhackers report on the new capabilities of the Still Toolkit and its impact.
Securelist

Community

Browse all →