Securelist Armored Likho Expands Cyber-Espionage with New Rust Toolkit
Article Content
- •Armored Likho's new campaign targets various sectors in Russia using a fake donation app.
- •The Still Toolkit includes components for stealing Telegram data and conducting audio surveillance.
- •Kaspersky identifies the malware as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.
In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and educational institutions. The attackers employed a fraudulent donation-service application as the initial infection vector. The campaign features a new Rust-based toolkit called the Still Toolkit, which includes components for hijacking Telegram sessions and conducting audio surveillance via compromised Windows devices. The Still Sync component steals Telegram session data, while Still Audio records conversations and transmits them to a command-and-control server. The malicious app masquerades as a legitimate donation service, deceiving users into providing access. Kaspersky products detect the threat as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic. This campaign shows significant overlap with previous Armored Likho activities documented in November 2024, February 2026, and July 2026. The distribution method for the fake app remains unknown as of this writing.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track APT41, AppleJeus and 3CX in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Advanced PHP Web Shell Exploits F5 BIG-IP Systems A sophisticated Linux implant targeting F5 BIG-IP Access Policy Management (APM) environments has been identified, exploiting CVE-2025-53521, an unauthenticated remote code execution vulnerability. This malware, referred to as 'PoisonedRefresh,' employs advanced techniques like function hooking and memory-only web…