Securelist
Armored Likho Expands Cyber-Espionage with New Rust Toolkit
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and educational institutions. The attackers employed a fraudulent donation-service application as the initial infection vector. The campaign features a new Rust-based toolkit called the Still Toolkit, which includes components for hijacking Telegram sessions and conducting audio surveillance via compromised Windows devices. The Still Sync component steals Telegram session data, while Still Audio records conversations and transmits them to a command-and-control server. The malicious app masquerades as a legitimate donation service, deceiving users into providing access. Kaspersky products detect the threat as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic. This campaign shows significant overlap with previous Armored Likho activities documented in November 2024, February 2026, and July 2026. The distribution method for the fake app remains unknown as of this writing.
Key Points: • Armored Likho's new campaign targets various sectors in Russia using a fake donation app. • The Still Toolkit includes components for stealing Telegram data and conducting audio surveillance. • Kaspersky identifies the malware as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.